6.7

CVE-2024-39438

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version13.0
   UnisocS8000 Version-
   UnisocSc7731e Version-
   UnisocSc9832e Version-
   UnisocSc9863a Version-
   UnisocT310 Version-
   UnisocT606 Version-
   UnisocT610 Version-
   UnisocT612 Version-
   UnisocT616 Version-
   UnisocT618 Version-
   UnisocT760 Version-
   UnisocT770 Version-
   UnisocT820 Version-
GoogleAndroid Version14.0
   UnisocS8000 Version-
   UnisocSc7731e Version-
   UnisocSc9832e Version-
   UnisocSc9863a Version-
   UnisocT310 Version-
   UnisocT606 Version-
   UnisocT610 Version-
   UnisocT612 Version-
   UnisocT616 Version-
   UnisocT618 Version-
   UnisocT760 Version-
   UnisocT770 Version-
   UnisocT820 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.133
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security@unisoc.com 6.5 0.6 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.