Missing Permission Check Vulnerability in Unisoc Telecom Service
CVE-2023-42743
7.8HIGH
Key Information:
- Vendor
- Unisoc
- Vendor
- CVE Published:
- 4 December 2023
Summary
A vulnerability has been identified in Unisoc's telecom service that involves a potential missing permission check. This flaw could allow an attacker to escalate privileges locally without requiring any additional execution permissions. Due to this vulnerability, there is an increased risk of unauthorized access to sensitive parts of the telecom service, which could compromise system integrity and user security.
Affected Version(s)
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000 Android11/Android12/Android13
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved