CVE-2023-40638: Medium severity Google Android vulnerability
Published Oct 2, 2023
·Updated
In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
Affected Software
6 affected components
Google Android=11.0
UNISOC S8000
UNISOC T760
UNISOC T770
UNISOC T820
Google Android
Event History
Oct 2, 2023
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Oct 8, 2023
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40638.
2
What is the severity of CVE-2023-40638?
The severity of CVE-2023-40638 is high.
3
What is the affected software?
The affected software is Google Android.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker with local access to the Telecom service, granting them unauthorized access and potentially causing a denial of service with system execution privileges.
5
Are there any recommended fixes or patches available for CVE-2023-40638?
Yes, it is recommended to apply the latest security patch provided by Google for Android to mitigate this vulnerability.