PT-2022-21804 · Unknown · Telephonyui

Dzmitry Lukyanenka

·

Published

2022-07-11

·

Updated

2023-06-29

·

CVE-2022-33689

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TelephonyUI versions prior to SMR Jul-2022 Release 1
Description The issue is related to improper access control in TelephonyUI, allowing attackers to modify the preferred network type through an unprotected binder call.
Recommendations For versions prior to SMR Jul-2022 Release 1, update to SMR Jul-2022 Release 1 or later to resolve the issue.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-33689

Affected Products

Telephonyui