目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-38295— Tcl 安全漏洞

AI 预测 7.5 利用难度: 较易 EPSS 0.18% · P8
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-38295 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that provides no protection at runtime. The missing permission is required as an access permission by components in various pre-installed apps. On the TCL 30Z device, the vulnerable app has a package name of com.tcl.screenrecorder (versionCode='1221092802', versionName='v5.2120.02.12008.1.T' ; versionCode='1221092805', versionName='v5.2120.02.12008.2.T'). On the TCL 10L device, the vulnerable app has a package name of com.tcl.sos (versionCode='2020102827', versionName='v3.2014.12.1012.B'). When a third-party app declares and requests the missing permission, it can interact with certain service components in the aforementioned apps (that execute with "system" privileges) to perform arbitrary files reads/writes in its context. An app exploiting this vulnerability only needs to declare and request the single missing permission and no user interaction is required beyond installing and running a third-party app. The software build fingerprints for each confirmed vulnerable device are as follows: TCL 10L (TCL/T770B/T1_LITE:11/RKQ1.210107.001/8BIC:user/release-keys) and TCL 30Z (TCL/4188R/Jetta_ATT:12/SP1A.210812.016/LV8E:user/release-keys, TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU5P:user/release-keys, TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU61:user/release-keys, TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU66:user/release-keys, TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU68:user/release-keys, TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU6P:user/release-keys, and TCL/T602DL/Jetta_TF:12/SP1A.210812.016/vU6X:user/release-keys). This malicious app declares the missing permission named com.tct.smart.switchphone.permission.SWITCH_DATA as a normal permission, requests the missing permission, and uses it to interact with the com.tct.smart.switchdata.DataService service component that is declared in vulnerable apps that execute with "system" privileges to perform arbitrary file reads/writes.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Tcl 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Tcl是一个免费可用的开源包。提供了一个强大的平台,用于创建将各种应用程序、协议、设备和框架联系在一起的集成应用程序。 TCL 30Z 、TCL 10 存在安全漏洞,该漏洞源于设备的某些软件版本包含易受攻击的预装应用程序(com.tcl.screenrecorder),该应用程序缺少权限,在运行时不提供任何保护。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
-n/a n/a -

二、漏洞 CVE-2023-38295 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-38295 的情报信息

登录查看更多情报信息。

CVE-2023-38295 其他参考 (1)

同批安全公告 · n/a · 2024-04-22 · 共 44 条

CVE-2023-38301vendor.gsm.serial 安全漏洞
CVE-2023-38290com.evenwell.fqc 安全漏洞
CVE-2023-38300Verizon Orbic Maui 安全漏洞
CVE-2023-38302flask-cors 安全漏洞
CVE-2023-38293Nokia C100 安全漏洞
CVE-2023-38294Itel Vision 3 Turbo 安全漏洞
CVE-2023-38291TCL 20XE和TCL 10L 安全漏洞
CVE-2023-38292TCL 20XE 安全漏洞
CVE-2023-38298TCL 安全漏洞
CVE-2023-38297com.factory.mmigroup 安全漏洞
CVE-2023-38299多款产品 安全漏洞
CVE-2022-34561phpFox 跨站脚本漏洞
CVE-2022-34560phpFox 安全漏洞
CVE-2022-34562phpFox 跨站脚本漏洞
CVE-2022-46897编号已被CVE保留
CVE-2022-35503Open Source MANO 安全漏洞
CVE-2024-27574Trainme Academy 安全漏洞
CVE-2024-29661Desdev DedeCMS 安全漏洞
CVE-2024-29368moziloCMS 安全漏洞
CVE-2024-29376Sylius 安全漏洞

显示前 20 条,共 44 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-38295

暂无评论


发表评论