Summary
- Security CVES
- High CVE-2023-33913
- Medium CVE-2023-33906,CVE-2023-33907,CVE-2023-33908,CVE-2023-33909,CVE-2023-33910,CVE-2023-33911,CVE-2023-33912,CVE-2022-47350,CVE-2022-47351,CVE-2023-3630
Minutia
- CVE ID CVE-2023-33906
- Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts Service
- Description
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200 Exposure of Sensitive Information to an Unauthorized Act
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2023-33907
- Title Missing Authorization in Contacts Service
- Description
In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-862 Missing Authorization
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2023-33908
- Title Exposure of Sensitive Information to an Unauthorized Actor in ims service
- Description
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200 Exposure of Sensitive Information to an Unauthorized Act
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12
- CVE ID CVE-2023-33909
- Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts service
- Description
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2023-33910
- Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts Service
- Description
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2023-33911
- Title Exposure of Sensitive Information to an Unauthorized Actor in vowifi service
- Description
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4
- CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T606/T612/T616/T610/T618
- Affected Software Versions
Android9/Android10/Android11
- CVE ID CVE-2023-33912
- Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts service
- Description
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- Technology Area Android
- Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.2
- CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Affected Chipsets*
SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2022-47350
- Title Out-of-bounds Read in camera driver
- Description
In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- Technology Area Kernel
- Vulnerability Type CWE-125 Out-of-bounds Read
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.4
- CVSS String CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Affected Chipsets*
SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android11/Android12/Android13
- CVE ID CVE-2022-47351
- Title Out-of-bounds Read in camera driver
- Description
In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
- Technology Area Kernel
- Vulnerability Type CWE-125 Out-of-bounds Read
- Access Vector Local
- CVSS Rating Medium
- CVSS Score 4.4
- CVSS String CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Affected Chipsets*
T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android13/Android11/Android12
- CVE ID CVE-2023-33913
- Title Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in DRM/oemcrypto
- Description
In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed
- Technology Area Android
- Vulnerability Type CWE-120BufferCopywithoutCheckingSizeofInputClassicBufferOverflow
- Access Vector Adjacent
- CVSS Rating High
- CVSS Score 7.1
- CVSS String CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
- Affected Chipsets*
T606/T612/T616/T610/T618/T760/T770/T820/S8000
- Affected Software Versions
Android12/Android11
- CVE ID CVE-2023-3630
- Title Comparison Logic is Vulnerable to Power Side-Channel Attacks in Mocor system
- Description
In Mocor system there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges
- Technology Area Mocor
- Vulnerability Type CWE-1255: ComparisonLogicisVulnerabletoPowerSide-ChannelAttacks
- Access Vector Physical
- CVSS Rating Medium
- CVSS Score 6.1
- CVSS String CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Affected Chipsets*
Mocor platforms
- Affected Software Versions
Mocor
*The list of affected chipsets may not be complete. For latest information, device OEMs can contact directly at https://unisupport.unisoc.com
Vulnerability type definition
- Abbreviation Interpretation
- RCE Remote Code Execution
- EoP Elevation of Privilege
- ID Information Disclosure
- DoS Denial of Service
- N/A Classification not available
Version
- Version Date Description
- 1.0 2023-08-04