SB2023100252 - Multiple vulnerabilities in Unisoc chipsets



SB2023100252 - Multiple vulnerabilities in Unisoc chipsets

Published: October 2, 2023

Security Bulletin ID SB2023100252
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 24
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 13% Low 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 24 vulnerabilities.


1) Information exposure (CVE-ID: CVE-2023-40645)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


2) Missing Authorization (CVE-ID: CVE-2023-40638)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to crash the entire system.

The vulnerability exists due to a possible missing permission check within the Telecom service in Android. A local application can crash the entire system.


3) Improper Access Control (CVE-ID: CVE-2023-40654)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the FW-PackageManager in Android. A remote attacker can trick the victim to open a specially crafted file and gain access to sensitive information.


4) Improper Access Control (CVE-ID: CVE-2023-40653)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the FW-PackageManager in Android. A remote attacker can trick the victim to open a specially crafted file and gain access to sensitive information.


5) Out-of-bounds write (CVE-ID: CVE-2023-40652)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local privileged application to damange or delete data.

The vulnerability exists due to a possible out of bounds write due to improper input validation within the jpg driver in Android. A local privileged application can damange or delete data.


6) Out-of-bounds write (CVE-ID: CVE-2023-40651)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the urild service in Android. A local privileged application can execute arbitrary code.


7) Information exposure (CVE-ID: CVE-2023-40650)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the Telecom service in Android. A remote attacker can trick the victim to open a specially crafted file and read and manipulate data.


8) Information exposure (CVE-ID: CVE-2023-40649)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


9) Information exposure (CVE-ID: CVE-2023-40648)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


10) Information exposure (CVE-ID: CVE-2023-40647)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


11) Information exposure (CVE-ID: CVE-2023-40646)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


12) Information exposure (CVE-ID: CVE-2023-40644)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


13) Information exposure (CVE-ID: CVE-2023-40631)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Dialer in Android. A local application can gain access to sensitive information.


14) Information exposure (CVE-ID: CVE-2023-40643)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


15) Information exposure (CVE-ID: CVE-2023-40642)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


16) Information exposure (CVE-ID: CVE-2023-40641)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


17) Improper Access Control (CVE-ID: CVE-2023-40640)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the SoundRecorder service in Android. A local application can read and manipulate data.


18) Improper Access Control (CVE-ID: CVE-2023-40639)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the SoundRecorder service in Android. A local application can read and manipulate data.


19) Information exposure (CVE-ID: CVE-2023-40637)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the telecom service in Android. A local application can gain access to sensitive information.


20) Comparison Logic is Vulnerable to Power Side-Channel Attacks (CVE-ID: CVE-2023-40636)

CWE-ID: CWE-1255 - Comparison Logic is Vulnerable to Power Side-Channel Attacks

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible way to write permission usage records of an app due to a missing permission check within the telecom service in Android. A local application can gain access to sensitive information.


21) Missing Authorization (CVE-ID: CVE-2023-40635)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to perform service disruption.

The vulnerability exists due to a possible missing permission check within the linkturbo in Android. A local application can perform service disruption.


22) Information exposure (CVE-ID: CVE-2023-40634)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the phasechecksercer in Android. A local application can gain access to sensitive information.


23) Information exposure (CVE-ID: CVE-2023-40633)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the phasecheckserver in Android. A local application can gain access to sensitive information.


24) Use After Free (CVE-ID: CVE-2023-40632)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a possible use after free due to a logic error within the jpg driver in Android. A local privileged application can execute arbitrary code.


Remediation

Install update from vendor's website.