Lucene search

K
cveUnisocCVE-2023-42720
HistoryDec 04, 2023 - 1:15 a.m.

CVE-2023-42720

2023-12-0401:15:10
CWE-125
Unisoc
web.nvd.nist.gov
10
cve
2023
42720
video service
out of bounds read
missing bounds check
local denial of service

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%

In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

Affected configurations

Nvd
Node
googleandroidMatch11.0-
AND
unisocs8000Match-
OR
unisoct760Match-
OR
unisoct770Match-
OR
unisoct820Match-
VendorProductVersionCPE
googleandroid11.0cpe:2.3:o:google:android:11.0:-:*:*:*:*:*:*
unisocs8000-cpe:2.3:h:unisoc:s8000:-:*:*:*:*:*:*:*
unisoct760-cpe:2.3:h:unisoc:t760:-:*:*:*:*:*:*:*
unisoct770-cpe:2.3:h:unisoc:t770:-:*:*:*:*:*:*:*
unisoct820-cpe:2.3:h:unisoc:t820:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "T760/T770/T820/S8000",
    "versions": [
      {
        "version": "Android11",
        "status": "affected"
      }
    ],
    "vendor": "Unisoc (Shanghai) Technologies Co., Ltd."
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2023-42720