« Back to list

CVE-2023-42748

Status: ModifiedHigh (7.8)—

In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-42748",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@unisoc.com",
      "affectedData": [
        {
          "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
          "product": "SC7731E/SC9832E/SC9863A/T310/T606/T612/T616/T610/T618/T760/T770/T820/S8000",
          "versions": [
            {
              "status": "affected",
              "version": "Android11/Android12/Android13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-04T01:15:12.000",
  "references": [
    {
      "url": "https://www.unisoc.com/en_us/secy/announcementDetail/https://www.unisoc.com/en_us/secy/announcementDetail/1731138365803266049",
      "tags": [
        "Broken Link"
      ],
      "source": "security@unisoc.com"
    },
    {
      "url": "https://www.unisoc.com/en_us/secy/announcementDetail/https://www.unisoc.com/en_us/secy/announcementDetail/1731138365803266049",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed"
    },
    {
      "lang": "es",
      "value": "En telecom service, es posible que falte una verificación de permiso. Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales."
    }
  ],
  "lastModified": "2026-06-17T06:24:25.633",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109DD7FD-3A48-4C3D-8E1A-4433B98E1E64"
            },
            {
              "criteria": "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8FB8EE9-FC56-4D5E-AE55-A5967634740C"
            },
            {
              "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:unisoc:s8000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FDE05D06-C798-4217-8858-8C5DC2C94751"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:sc7731e:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC867249-B767-4802-868D-6D0E356C8294"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:sc9832e:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "25BBD3C5-E87C-4730-970C-19DF855AC3A2"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:sc9863a:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE00DFDE-97DD-4D33-B580-73FEF677C71B"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t310:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F20E00D8-2F00-4FA3-9455-37DC89908D96"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t606:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "905E39DD-7948-40A4-B042-EBB9A9591347"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t610:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CDC980D6-B797-4AE1-B553-35395AE80D07"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t612:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "98408A48-561A-49D1-967F-834311742B7F"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t616:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "756E5850-CDC7-46C2-BAFC-1E2A359A2709"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t618:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "39002ECE-636A-4FEB-9A0B-8127E8AAC844"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t760:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3D965CCA-C963-49E4-ACF0-2A9F458AF470"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t770:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FFEF06A-E3E0-486F-89CC-D52FF3F26F0B"
            },
            {
              "criteria": "cpe:2.3:h:unisoc:t820:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49601008-D3FF-47CC-B961-6FDDFC7A0596"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@unisoc.com"
}