SB2023090401 - Multiple vulnerabilities in Unisoc chipsets
Published: September 4, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 43 vulnerabilities.
1) Information exposure (CVE-ID: CVE-2023-38443)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
2) Information exposure (CVE-ID: CVE-2023-33916)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
3) Information exposure (CVE-ID: CVE-2023-38442)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
4) Information exposure (CVE-ID: CVE-2023-33917)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
5) Information exposure (CVE-ID: CVE-2023-33918)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
6) Information exposure (CVE-ID: CVE-2023-38436)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
7) Information exposure (CVE-ID: CVE-2023-38437)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
8) Information exposure (CVE-ID: CVE-2023-38438)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
9) Information exposure (CVE-ID: CVE-2023-38439)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
10) Information exposure (CVE-ID: CVE-2023-38440)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
11) Information exposure (CVE-ID: CVE-2023-38441)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
12) Information exposure (CVE-ID: CVE-2023-38454)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
13) Information exposure (CVE-ID: CVE-2023-38453)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
14) Information exposure (CVE-ID: CVE-2023-38444)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
15) Information exposure (CVE-ID: CVE-2023-38445)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
16) Information exposure (CVE-ID: CVE-2023-38446)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
17) Information exposure (CVE-ID: CVE-2023-38447)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
18) Information exposure (CVE-ID: CVE-2023-38448)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
19) Information exposure (CVE-ID: CVE-2023-38449)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
20) Information exposure (CVE-ID: CVE-2023-38450)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
21) Information exposure (CVE-ID: CVE-2023-38451)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
22) Information exposure (CVE-ID: CVE-2023-38452)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
23) Out-of-bounds write (CVE-ID: CVE-2023-38467)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the Android. A local privileged application can execute arbitrary code.
24) Information exposure (CVE-ID: CVE-2023-38457)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
25) Information exposure (CVE-ID: CVE-2023-38458)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
26) Information exposure (CVE-ID: CVE-2023-38459)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
27) Information exposure (CVE-ID: CVE-2023-38460)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
28) Information exposure (CVE-ID: CVE-2023-38461)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
29) Information exposure (CVE-ID: CVE-2023-38462)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
30) Information exposure (CVE-ID: CVE-2023-38463)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
31) Information exposure (CVE-ID: CVE-2023-38464)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
32) Missing Authorization (CVE-ID: CVE-2023-38466)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local privileged application can gain access to sensitive information.
33) Information exposure (CVE-ID: CVE-2023-38455)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
34) Missing Authorization (CVE-ID: CVE-2023-38465)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local privileged application can gain access to sensitive information.
35) Out-of-bounds write (CVE-ID: CVE-2023-38468)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the Android. A local privileged application can execute arbitrary code.
36) Out-of-bounds write (CVE-ID: CVE-2023-38553)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the WCN. A local application can read and manipulate data.
37) Out-of-bounds write (CVE-ID: CVE-2023-38554)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged application to perform a denial of service (DoS) attack.
The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the WCN. A local privileged application can perform a denial of service (DoS) attack.
38) Out-of-bounds read (CVE-ID: CVE-2022-47352)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to manipulate or delete data.
The vulnerability exists due to a possible out of bounds read due to a missing bounds check within the Kernel. A local application can manipulate or delete data.
39) Missing Authorization (CVE-ID: CVE-2022-48452)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to manipulate or delete data.
The vulnerability exists due to a possible missing permission check within the Android. A local application can manipulate or delete data.
40) Out-of-bounds write (CVE-ID: CVE-2022-48453)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local application to manipulate or delete data.
The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the Kernel. A local application can manipulate or delete data.
41) Improper Handling of Missing Values (CVE-ID: CVE-2023-33914)
CWE-ID: CWE-230 - Improper Handling of Missing Values
CVSSv4: 6.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote application to read, manipulate or delete data.
The vulnerability exists due to a possible missing verification incorrect input within the Security Mode Command in Modem. A remote application can read, manipulate or delete data.
42) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2023-33915)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to a possible missing permission check within the Modem. A remote attacker can read and manipulate data.
43) Information exposure (CVE-ID: CVE-2023-38456)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a possible missing permission check within the Android. A local application can gain access to sensitive information.
Remediation
Install update from vendor's website.