PT-2024-10778 · Unknown · Vivo Framework

Kailong Wang

+1

·

Published

2024-11-25

·

Updated

2024-11-25

·

CVE-2020-12491

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vivo Framework (affected versions not specified)
Description The issue is related to improper control of framework service permissions, which may lead to the leakage of some sensitive device information. It is also described as a missing authentication flaw that could allow unauthorized access to the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-12491

Affected Products

Vivo Framework