Description
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
Published: 2023-06-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-29584 There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear personal data and applications on the user's device, affecting device operation.
History

Thu, 12 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Zte Up T2 4k Up T2 4k Firmware Zxv10 B860h V5d0 Zxv10 B860h V5d0 Firmware Zxv10 B866v2 Zxv10 B866v2-h Zxv10 B866v2-h Firmware Zxv10 B866v2 Firmware Zxv10 B866v2f Zxv10 B866v2f Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-12-12T17:14:29.564Z

Reserved: 2023-02-09T00:00:00.000Z

Link: CVE-2023-25645

cve-icon Vulnrichment

Updated: 2024-08-02T11:25:19.247Z

cve-icon NVD

Status : Modified

Published: 2023-06-16T19:15:14.527

Modified: 2024-12-12T18:15:22.180

Link: CVE-2023-25645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses