Missing Permission Check in Dialer Service Affects Unisoc Products
CVE-2022-48440

5.5MEDIUM

What is CVE-2022-48440?

A vulnerability exists in the dialer service of Unisoc products, attributed to a lack of adequate permission checks. This oversight may allow attackers to exploit the service, potentially leading to a local denial of service. It is crucial for users of Unisoc products to be aware of this issue and ensure their systems are secured against potential local access to the dialer.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10/Android11/Android12/Android13

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.