CVE-2025-58107 PUBLISHED

Assigner: mitre
Reserved: 25.08.2025 Published: 02.03.2026 Updated: 02.03.2026

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text