Learn about CVE-2022-47475 affecting Unisoc products, enabling local information disclosure in telephony services. Find mitigation steps and affected systems here.
This article provides insights into CVE-2022-47475, a vulnerability impacting Unisoc (Shanghai) Technologies Co., Ltd. products, leading to local information disclosure in telephony services.
Understanding CVE-2022-47475
CVE-2022-47475 is a vulnerability that affects Unisoc (Shanghai) Technologies Co., Ltd. products, specifically SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820, and S8000 running Android 10 and Android 11.
What is CVE-2022-47475?
In telephony service, there is a missing permission check in Unisoc products. This gap could potentially allow local information disclosure without requiring additional execution privileges.
The Impact of CVE-2022-47475
The vulnerability poses a risk of local information disclosure, which could be exploited by malicious actors to access sensitive data without the need for elevated privileges.
Technical Details of CVE-2022-47475
The following technical details outline the specifics of CVE-2022-47475:
Vulnerability Description
The missing permission check in telephony services can be leveraged to disclose local information, presenting a security risk.
Affected Systems and Versions
Unisoc products including SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820, and S8000 running Android 10 and Android 11 are impacted by this vulnerability.
Exploitation Mechanism
The vulnerability allows threat actors to exploit the missing permission check in telephony services to extract sensitive information locally.
Mitigation and Prevention
To address CVE-2022-47475, consider the following mitigation strategies:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Stay informed about patch releases from Unisoc and apply them to affected devices to mitigate the risk of local information disclosure.