Vulnerabilidades em Unisoc (Shanghai) Technologies Co., Ltd.

656 resultados
Análise Vexday

Com 647 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, a Unisoc apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere baixa pressão ofensiva documentada no momento. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), padrão que, quando explorado, permite acesso não autorizado a recursos ou funcionalidades restritas e merece atenção especial em revisões de código e hardening. A CVE mais relevante no contexto atual é CVE-2025-31715, com escore EPSS de 0,0156, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado seu destaque entre as ameaças ativas. As 6 vulnerabilidades surgidas nos últimos 90 dias e a ausência de PoCs públicas apontam para um perfil de risco moderado, embora a presença de 4 CVEs críticas reforce a necessidade de acompanhamento contínuo das atualizações do fabricante.

CVE-2023-48357MEDIUMIn vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2023-40631—In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges neEPSS 0.1%CVE-2023-40652—In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with SysEPSS 0.1%CVE-2023-48356MEDIUMIn jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2023-40653—In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution pEPSS 0.1%CVE-2023-40638—In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privilegeEPSS 0.1%CVE-2023-48358MEDIUMIn drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2023-48355MEDIUMIn jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2023-48359MEDIUMIn autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service witEPSS 0.1%CVE-2023-48339MEDIUMIn jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privilegeEPSS 0.1%CVE-2023-48354MEDIUMIn telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execEPSS 0.1%CVE-2022-48460—In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with EPSS 0.1%CVE-2023-48348MEDIUMIn video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with EPSS 0.1%CVE-2023-48346MEDIUMIn video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2023-38447—In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution priviEPSS 0.1%CVE-2022-48459—In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additiEPSS 0.1%CVE-2023-38448—In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution priviEPSS 0.1%CVE-2022-48458—In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additiEPSS 0.1%CVE-2022-48455—In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no aEPSS 0.1%CVE-2022-48457—In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additiEPSS 0.1%