CVE-2023-25647

There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:axon_30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zte:axon_40_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_pro:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zte:axon_40_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_ultra:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:zte:nubia_z50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:nubia_z50:-:*:*:*:*:*:*:*

History

24 Aug 2023, 16:20

Type Values Removed Values Added
First Time Zte axon 30 Firmware
Zte axon 30
Zte axon 40 Pro Firmware
Zte
Zte nubia Z50 Firmware
Zte axon 40 Pro
Zte axon 40 Ultra
Zte axon 40 Ultra Firmware
Zte nubia Z50
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CPE cpe:2.3:o:zte:axon_30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zte:nubia_z50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_ultra:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:axon_40_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_40_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:zte:nubia_z50:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:axon_40_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:axon_30:-:*:*:*:*:*:*:*
References (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032264 - (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032264 - Vendor Advisory
CWE CWE-863

17 Aug 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-17 03:15

Updated : 2023-08-24 16:20


NVD link : CVE-2023-25647

Mitre link : CVE-2023-25647


JSON object : View

Products Affected

zte

  • axon_40_pro
  • axon_40_ultra
  • axon_30
  • axon_40_ultra_firmware
  • nubia_z50
  • axon_30_firmware
  • axon_40_pro_firmware
  • nubia_z50_firmware
CWE
CWE-863

Incorrect Authorization