Security Bulletin

Summary
  • Security CVES
  • High CVE-2023-33913
  • Medium CVE-2023-33906,CVE-2023-33907,CVE-2023-33908,CVE-2023-33909,CVE-2023-33910,CVE-2023-33911,CVE-2023-33912,CVE-2022-47350,CVE-2022-47351,CVE-2023-3630
Minutia
  • CVE ID CVE-2023-33906
  • Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts Service
  • Description

    In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200 Exposure of Sensitive Information to an Unauthorized Act
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2023-33907
  • Title Missing Authorization in Contacts Service
  • Description

    In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-862 Missing Authorization
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2023-33908
  • Title Exposure of Sensitive Information to an Unauthorized Actor in ims service
  • Description

    In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200 Exposure of Sensitive Information to an Unauthorized Act
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12

  • CVE ID CVE-2023-33909
  • Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts service
  • Description

    In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2023-33910
  • Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts Service
  • Description

    In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2023-33911
  • Title Exposure of Sensitive Information to an Unauthorized Actor in vowifi service
  • Description

    In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T606/T612/T616/T610/T618

  • Affected Software Versions

    Android9/Android10/Android11

  • CVE ID CVE-2023-33912
  • Title Exposure of Sensitive Information to an Unauthorized Actor in Contacts service
  • Description

    In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

  • Technology Area Android
  • Vulnerability Type CWE-200Exposureof Sensitive Information to anUnauthorizedActor
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.2
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
  • Affected Chipsets*

    SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2022-47350
  • Title Out-of-bounds Read in camera driver
  • Description

    In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • Technology Area Kernel
  • Vulnerability Type CWE-125 Out-of-bounds Read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.4
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
  • Affected Chipsets*

    SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android11/Android12/Android13

  • CVE ID CVE-2022-47351
  • Title Out-of-bounds Read in camera driver
  • Description

    In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • Technology Area Kernel
  • Vulnerability Type CWE-125 Out-of-bounds Read
  • Access Vector Local
  • CVSS Rating Medium
  • CVSS Score 4.4
  • CVSS String CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
  • Affected Chipsets*

    T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android13/Android11/Android12

  • CVE ID CVE-2023-33913
  • Title Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in DRM/oemcrypto
  • Description

    In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed

  • Technology Area Android
  • Vulnerability Type CWE-120BufferCopywithoutCheckingSizeofInputClassicBufferOverflow
  • Access Vector Adjacent
  • CVSS Rating High
  • CVSS Score 7.1
  • CVSS String CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Affected Chipsets*

    T606/T612/T616/T610/T618/T760/T770/T820/S8000

  • Affected Software Versions

    Android12/Android11

  • CVE ID CVE-2023-3630
  • Title Comparison Logic is Vulnerable to Power Side-Channel Attacks in Mocor system
  • Description

    In Mocor system there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges

  • Technology Area Mocor
  • Vulnerability Type CWE-1255: ComparisonLogicisVulnerabletoPowerSide-ChannelAttacks
  • Access Vector Physical
  • CVSS Rating Medium
  • CVSS Score 6.1
  • CVSS String CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Affected Chipsets*

    Mocor platforms

  • Affected Software Versions

    Mocor

*The list of affected chipsets may not be complete. For latest information, device OEMs can contact directly at https://unisupport.unisoc.com

Vulnerability type definition
  • Abbreviation Interpretation
  • RCE Remote Code Execution
  • EoP Elevation of Privilege
  • ID Information Disclosure
  • DoS Denial of Service
  • N/A Classification not available
Version
  • Version Date Description
  • 1.0 2023-08-04