Permissions, Privileges, and Access Controls in UNISOC products - CVE-2021-1049
Published: January 9, 2022 / Updated: March 7, 2023
Vulnerability identifier: #VU59325
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1049
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a malicious application to read arbitrary files on the system.
The vulnerability exists due to improper permissions in the Unisoc slogmodem. A local application can read arbitrary files on the system.
Affected software
SC9863A
SC9832E
SC7731E
UMS512
UMS312
UMS9230
UMS9620
Google Android
SC9832E
SC7731E
UMS512
UMS312
UMS9230
UMS9620
Google Android
How to mitigate CVE-2021-1049
Install updates from vendor's website.
Google Android - addressed in versions 9 2022-01-05, 10 2022-01-05, 11 2022-01-05, 12 2022-01-05