CVE-2022-48440
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
| Running on/with | Platform Versions |
|---|---|
Unisoc S8000 | All versions |
Unisoc Sc7731e | All versions |
Unisoc Sc9832e | All versions |
Unisoc Sc9863a | All versions |
Unisoc T310 | All versions |
Unisoc T606 | All versions |
Unisoc T610 | All versions |
Unisoc T612 | All versions |
Unisoc T616 | All versions |
Unisoc T618 | All versions |
Unisoc T760 | All versions |
Unisoc T770 | All versions |
Unisoc T820 | All versions |
Related CWEs
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CWE-862
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
References (2)
Source: security@unisoc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.