CVE-2022-38695

7.8

Unisoc · SC9863A, T310, T610, T618, T606, T612, T616, T760, T770, T820, S8000

A vulnerability in the Unisoc BootRom involving an unchecked command index allows for local privilege escalation.

Executive summary

A critical security flaw in multiple Unisoc System-on-Chip (SoC) BootRom components could allow a local attacker to achieve full privilege escalation on the affected device.

Vulnerability

The vulnerability exists within the BootRom, where an unchecked command index can be manipulated. This flaw allows a local user to escalate privileges without requiring additional execution permissions.

Business impact

The ability to perform local privilege escalation poses a significant risk to data integrity and device security. A successful exploit grants the attacker elevated control over the device, which could lead to the theft of sensitive user data, unauthorized access to system functions, or persistent compromise. With a CVSS score of 7.8, this vulnerability is classified as High severity, necessitating prompt attention to mitigate potential unauthorized access.

Remediation

Immediate Action: Contact the device manufacturer or firmware provider to determine if a security update addressing this BootRom vulnerability is available for your specific hardware model.

Proactive Monitoring: Monitor device logs for unusual behavior or unauthorized attempts to access system-level commands that typically require elevated privileges.

Compensating Controls: Ensure that device storage is encrypted and that access to the physical device is restricted to authorized personnel to prevent local exploitation attempts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the nature of this vulnerability, which resides in the foundational BootRom code, remediation options may be limited to vendor-supplied firmware updates. Security teams should prioritize identifying devices using the affected Unisoc chipsets and engage with vendors for patch availability. Immediate action is required to verify the security posture of these devices and ensure that protective measures are in place to prevent local access by unauthorized parties.

More Unisoc CVEs

Sources