4.7
CVE-2023-25647
- EPSS 0.06%
- Published 17.08.2023 03:15:09
- Last modified 21.11.2024 07:49:51
- Source psirt@zte.com.cn
- Teams watchlist Login
- Open Login
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
Data is provided by the National Vulnerability Database (NVD)
Zte ≫ Axon 30 Firmware Version < 3.0.0b06
Zte ≫ Axon 40 Pro Firmware Version < 1.0.0b16
Zte ≫ Axon 40 Ultra Firmware Version < 2.0.0b17
Zte ≫ Nubia Z50 Firmware Version < 1.0.0b19mr
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.197 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
psirt@zte.com.cn | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.