#VU78973 Comparison Logic is Vulnerable to Power Side-Channel Attacks in Mocor platforms


Published: 2023-08-05

Vulnerability identifier: #VU78973

Vulnerability risk: Medium

CVSSv3.1: 5.3 [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-3630

CWE-ID: CWE-1255

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Mocor platforms
Mobile applications / Mobile firmware & hardware

Vendor: UNISOC

Description

The vulnerability allows a local attacker to read and manipulate data.

The vulnerability exists due to a missing permission check within the Mocor system in Mocor. A local attacker can read and manipulate data.

Mitigation
Install security update from vendor's website.

Vulnerable software versions

Mocor platforms: All versions


External links
http://www.unisoc.com/en_us/secy/announcementDetail/1687281677639942145


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability