CVE-2025-20972

6.2
MEDIUMCVSS v3.1 Base Score
0.13%
LOW RiskEPSS (2nd percentile)
NVD-CWE-Other

Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

Published: 5/7/2025
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.2MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Score (Exploitation Probability)

0.13%LOW Exploitation Risk
2nd percentile

This vulnerability has a 0.13% probability of being exploited in the next 30 days, ranking higher than 2% of all scored CVEs.

CWE Classification

NVD-CWE-Other
Advertisement