Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13685 | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation. | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: SamsungMobile
Published:
Updated: 2025-05-07T14:39:19.056Z
Reserved: 2024-11-06T02:30:14.868Z
Link: CVE-2025-20974
Updated: 2025-05-07T14:39:12.438Z
Status : Deferred
Published: 2025-05-07T09:15:17.940
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-20974
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD