CVE-2022-47342
https://notcve.org/view.php?id=CVE-2022-47342
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-129: Improper Validation of Array Index •
CVE-2022-47341
https://notcve.org/view.php?id=CVE-2022-47341
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •
CVE-2022-47331
https://notcve.org/view.php?id=CVE-2022-47331
In wlan driver, there is a race condition. This could lead to local denial of service in wlan services. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-47339
https://notcve.org/view.php?id=CVE-2022-47339
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •
CVE-2023-20602
https://notcve.org/view.php?id=CVE-2023-20602
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALPS07494107. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-190: Integer Overflow or Wraparound •