Power Management Service Vulnerability in UniSoC Products
CVE-2022-39092

7.8HIGH

What is CVE-2022-39092?

In the power management service provided by UniSoC, a critical issue related to a missing permission check has been identified. This vulnerability allows for the configuration of the power management service without validating the required execution privileges, potentially compromising the integrity of the system. Exploiting this weakness could lead to unauthorized modifications and control over power management settings.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10/Android11/Android12

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.