MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-53077

CVSS 6.5v3.1pub. 2025-07-29upd. 2025-08-11

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  • Samsung Data Management Server

    HW
    Samsung
    all versions
  • Samsung Data Management Server Firmware

    OS
    Samsung
    2.0.0 – 2.3.13.1 (excl.)2.5.0.17 – 2.6.14.1 (excl.)2.7.0.15 – 2.9.3.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-53078HIGH8.0same product

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary...

CVE-2025-53080HIGH7.1same product

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management ...

CVE-2010-4284HIGH7.5same product

SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Ser...

CVE-2025-53079MEDIUM4.9same product

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) t...

CVE-2025-53081MEDIUM6.4same product

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files...