Missing Permission Check in Telephony Service of Unisoc Product
CVE-2022-48443

5.5MEDIUM

What is CVE-2022-48443?

The vulnerability in Unisoc's telephony service is characterized by a potential oversight in permission checks. This flaw could enable a local denial of service attack, leading to service interruptions without the need for elevated execution privileges. Ensuring proper access controls and permission validations is crucial to mitigating this risk and maintaining service reliability.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10/Android11/Android12

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.