Vulnerabilities in Unisoc (Shanghai) Technologies Co., Ltd.

656 results
Vexday analysis

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2022-47358MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2022-47483MEDIUMIn telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additionaEPSS 0.1%CVE-2022-47481MEDIUMIn telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additionaEPSS 0.1%CVE-2023-52345MEDIUMIn modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with SysEPSS 0.1%CVE-2022-48379MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2022-38685In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no EPSS 0.1%CVE-2022-48377MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2022-38676MEDIUMIn gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2022-47490MEDIUMIn soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privEPSS 0.1%CVE-2022-47484In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additionaEPSS 0.1%CVE-2022-38677MEDIUMIn cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional executioEPSS 0.1%CVE-2022-48375MEDIUMIn contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution pEPSS 0.1%CVE-2022-47359MEDIUMIn log service, there is a missing permission check. This could lead to local denial of service in log service.EPSS 0.1%CVE-2023-30929In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execEPSS 0.1%CVE-2023-30928In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execEPSS 0.1%CVE-2023-30916In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution prEPSS 0.1%CVE-2023-52346MEDIUMIn modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with SysEPSS 0.1%CVE-2022-39134MEDIUMIn audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2023-42750In gnss service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystEPSS 0.1%CVE-2023-38468In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%