CVE-2023-25647
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/08/2023
Last modified:
24/08/2023
Description
<br />
<br />
<br />
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.<br />
<br />
<br />
<br />
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zte:axon_30_firmware:*:*:*:*:*:*:*:* | 3.0.0b06 (excluding) | |
| cpe:2.3:h:zte:axon_30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:axon_40_pro_firmware:*:*:*:*:*:*:*:* | 1.0.0b16 (excluding) | |
| cpe:2.3:h:zte:axon_40_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:axon_40_ultra_firmware:*:*:*:*:*:*:*:* | 2.0.0b17 (excluding) | |
| cpe:2.3:h:zte:axon_40_ultra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zte:nubia_z50_firmware:*:*:*:*:*:*:*:* | 1.0.0b19mr (excluding) | |
| cpe:2.3:h:zte:nubia_z50:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



