LiveActive security incident?Get immediate response
CVE Record

CVE-2020-25055: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software.

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE affects Samsung mobile devices running Android 8.x, 9.0, or 10.0. If an attacker controls an unprivileged Secure Folder process, they may bypass administrative restrictions inside Knox Container. The public record does not provide CVSS scoring, affected model lists, or evidence of active exploitation.

Executive priority

Treat this as a managed-device hardening issue, not a confirmed mass-exploitation emergency. Prioritize older Samsung fleets that still rely on Knox Container or Secure Folder and verify they received Samsung’s relevant security update.

Technical view

Samsung’s persona service could allow an attacker with control of an unprivileged SecureFolder process to bypass admin restrictions in KnoxContainer. The issue is tracked as SVE-2020-18133 in Samsung’s August 2020 security materials. Source data does not define exact models, exploitability details, or a CVSS vector.

Likely exposure

Exposure is most relevant to Samsung Android 8.x, 9.0, and 10.0 devices using Knox Container or Secure Folder. Managed enterprise fleets with Knox policies have higher operational relevance. The source bundle does not identify specific device models or configurations beyond OS versions and services.

Exploitation context

CISA KEV is false, and the supplied sources do not cite active exploitation. The described attacker already controls an unprivileged SecureFolder process, so this is not evidenced as remote unauthenticated exploitation. The business concern is policy or admin-control bypass in managed Samsung environments.

Researcher notes

The public evidence is sparse: no CVSS, CWE, model list, proof-of-concept, or exploitation report is included. Analysis should remain bounded to persona service, SecureFolder process control, KnoxContainer admin restriction bypass, and Samsung’s SVE-2020-18133 reference.

Mitigation direction

  • Check Samsung guidance for SVE-2020-18133 from the August 2020 security update.
  • Apply applicable Samsung mobile security updates to affected Android 8.x, 9.0, and 10.0 devices.
  • Prioritize managed devices using Knox Container or Secure Folder.
  • Review MDM policy enforcement for Knox-managed restrictions.

Validation and detection

  • Inventory Samsung devices by Android version and security patch level.
  • Identify devices using Knox Container or Secure Folder.
  • Confirm whether Samsung August 2020 or later relevant updates are installed.
  • Check MDM records for Knox policy bypass symptoms or unexplained policy drift.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-25055 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.