Vulnerabilidades en Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análisis Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2023-42703In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2023-42713In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2023-42704In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to locEPSS 0.1%CVE-2023-42702In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2023-42700In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2023-42706MEDIUMIn firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2023-42732In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execuEPSS 0.1%CVE-2022-47361HIGHIn firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges EPSS 0.1%CVE-2023-42677In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to locEPSS 0.1%CVE-2023-42730In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to loEPSS 0.1%CVE-2023-42714In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead EPSS 0.1%CVE-2022-39119In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution priviEPSS 0.1%CVE-2023-42749In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lEPSS 0.1%CVE-2023-42737In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead tEPSS 0.1%CVE-2022-44421MEDIUMIn wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.EPSS 0.1%CVE-2023-42741In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead tEPSS 0.1%CVE-2022-42756HIGHIn sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2024-39428MEDIUMIn trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2022-48387MEDIUMthe apipe driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-48386MEDIUMthe apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution EPSS 0.1%