4.7

CVE-2023-25647



There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.



Data is provided by the National Vulnerability Database (NVD)
ZteAxon 30 Firmware Version < 3.0.0b06
   ZteAxon 30 Version-
ZteAxon 40 Pro Firmware Version < 1.0.0b16
   ZteAxon 40 Pro Version-
ZteAxon 40 Ultra Firmware Version < 2.0.0b17
   ZteAxon 40 Ultra Version-
ZteNubia Z50 Firmware Version < 1.0.0b19mr
   ZteNubia Z50 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.197
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
psirt@zte.com.cn 4.7 1 3.6
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.