6.7
CVE-2024-39437
- EPSS 0.05%
- Published 09.10.2024 07:15:08
- Last modified 17.10.2024 17:18:45
- Source security@unisoc.com
- Teams watchlist Login
- Open Login
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
Data is provided by the National Vulnerability Database (NVD)
Google ≫ Android Version13.0
Unisoc ≫ S8000 Version-
Unisoc ≫ Sc7731e Version-
Unisoc ≫ Sc9832e Version-
Unisoc ≫ Sc9863a Version-
Unisoc ≫ T310 Version-
Unisoc ≫ T606 Version-
Unisoc ≫ T610 Version-
Unisoc ≫ T612 Version-
Unisoc ≫ T616 Version-
Unisoc ≫ T618 Version-
Unisoc ≫ T760 Version-
Unisoc ≫ T770 Version-
Unisoc ≫ T820 Version-
Unisoc ≫ Sc7731e Version-
Unisoc ≫ Sc9832e Version-
Unisoc ≫ Sc9863a Version-
Unisoc ≫ T310 Version-
Unisoc ≫ T606 Version-
Unisoc ≫ T610 Version-
Unisoc ≫ T612 Version-
Unisoc ≫ T616 Version-
Unisoc ≫ T618 Version-
Unisoc ≫ T760 Version-
Unisoc ≫ T770 Version-
Unisoc ≫ T820 Version-
Google ≫ Android Version14.0
Unisoc ≫ S8000 Version-
Unisoc ≫ Sc7731e Version-
Unisoc ≫ Sc9832e Version-
Unisoc ≫ Sc9863a Version-
Unisoc ≫ T310 Version-
Unisoc ≫ T606 Version-
Unisoc ≫ T610 Version-
Unisoc ≫ T612 Version-
Unisoc ≫ T616 Version-
Unisoc ≫ T618 Version-
Unisoc ≫ T760 Version-
Unisoc ≫ T770 Version-
Unisoc ≫ T820 Version-
Unisoc ≫ Sc7731e Version-
Unisoc ≫ Sc9832e Version-
Unisoc ≫ Sc9863a Version-
Unisoc ≫ T310 Version-
Unisoc ≫ T606 Version-
Unisoc ≫ T610 Version-
Unisoc ≫ T612 Version-
Unisoc ≫ T616 Version-
Unisoc ≫ T618 Version-
Unisoc ≫ T760 Version-
Unisoc ≫ T770 Version-
Unisoc ≫ T820 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.133 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
security@unisoc.com | 6.5 | 0.6 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.