A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper permission settings, third-party applications can read some files in the proc file system without authorization. Attackers could exploit this vulnerability to obtain sensitive information. This affects Axon 11 5G ZTE/CN_P725A12/P725A12:10/QKQ1.200816.002/20201116.175317:user/release-keys.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1015064 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: zte
Published: 2021-05-19T10:48:50
Updated: 2021-05-19T10:48:50
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-21732
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-05-19T11:15:07.757
Modified: 2022-06-28T14:11:45.273
Link: CVE-2021-21732
JSON object: View
Redhat Information
No data.
CWE