First published: Mon Apr 08 2024(Updated: )
In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
Credit: security@unisoc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Android | =12.0 | |
Android | =13.0 | |
Any of | ||
Unisoc S8000 Firmware | ||
Unisoc T760 Firmware | ||
Unisoc T770 | ||
Unisoc T820 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52341 is classified as a medium-severity vulnerability due to its potential for remote information disclosure.
To mitigate CVE-2023-52341, ensure that your affected devices are updated to the latest Android versions, 12.0 or 13.0, with security patches applied.
CVE-2023-52341 is caused by a missing permission check in the Plaintext COUNTER CHECK message before the activation of AS security.
CVE-2023-52341 affects devices running Android versions 12.0 and 13.0.
CVE-2023-52341 can be exploited to disclose sensitive information without requiring additional execution privileges.