CVE-2023-52341
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw allows an attacker to read sensitive information from a system before security is fully activated, by sending a specially crafted message. No special privileges are needed to exploit this.
Technical detail
Missing permission validation on COUNTER CHECK messages processed prior to AS security activation enables unauthenticated information disclosure. Attack vector is network-based with no preconditions; the vulnerability permits direct access to sensitive data without elevated privileges.
Summary generated and translated by AI from the official description.
In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Unisoc (Shanghai) Technologies Co., Ltd. · T760/T770/T820/S8000