4.7
CVE-2023-25647
- EPSS 0.06%
- Veröffentlicht 17.08.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:49:51
- Quelle psirt@zte.com.cn
- Teams Watchlist Login
- Unerledigt Login
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Axon 30 Firmware Version < 3.0.0b06
Zte ≫ Axon 40 Pro Firmware Version < 1.0.0b16
Zte ≫ Axon 40 Ultra Firmware Version < 2.0.0b17
Zte ≫ Nubia Z50 Firmware Version < 1.0.0b19mr
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.197 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
psirt@zte.com.cn | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.