Lucene search

K
cve[email protected]CVE-2023-25647
HistoryAug 17, 2023 - 3:15 a.m.

CVE-2023-25647

2023-08-1703:15:09
CWE-269
CWE-863
web.nvd.nist.gov
29
zte
mobile phones
access control
vulnerability
nvd
cve-2023-25647

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.6%

There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.

Affected configurations

NVD
Node
zteaxon_30Match-
AND
zteaxon_30_firmwareRange<3.0.0b06
Node
zteaxon_40_proMatch-
AND
zteaxon_40_pro_firmwareRange<1.0.0b16
Node
zteaxon_40_ultraMatch-
AND
zteaxon_40_ultra_firmwareRange<2.0.0b17
Node
ztenubia_z50Match-
AND
ztenubia_z50_firmwareRange<1.0.0b19mr

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Android"
    ],
    "product": "Some ZTE Mobile Phones",
    "vendor": "ZTE",
    "versions": [
      {
        "lessThanOrEqual": "V1.0.0B07",
        "status": "affected",
        "version": "NON_EEA_P870F21V1.0.0B01",
        "versionType": "V1.0.0B07"
      },
      {
        "lessThanOrEqual": "V1.0.0B18MR",
        "status": "affected",
        "version": " GEN_ZTE_PQ82A01V1.0.0B01MR",
        "versionType": "V1.0.0B18MR"
      },
      {
        "lessThanOrEqual": "V3.0.0B05",
        "status": "affected",
        "version": "GEN_ZTE_P870A01V3.0.0B01",
        "versionType": "V3.0.0B05"
      },
      {
        "lessThanOrEqual": "V2.0.0B16",
        "status": "affected",
        "version": "GEN_ZTE_P898A01V2.0.0B01",
        "versionType": "V2.0.0B16"
      }
    ]
  }
]

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.6%

Related for CVE-2023-25647