Local Denial of Service in Telephony Services by Unisoc
CVE-2022-48446

5.5MEDIUM

What is CVE-2022-48446?

In the telephony service provided by Unisoc, a potential missing permission check has been identified. This vulnerability may allow a local user to trigger a denial of service, affecting the availability of telephony features without requiring any additional execution privileges. This highlights the importance of robust permission verification mechanisms in critical service components.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10/Android11/Android12

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.