CRITICAL🇵🇱 Wersja polska

CVE-2024-1608

CVSS 9.1v3.1pub. 2024-02-20upd. 2025-04-02

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.

🤖 AI Analysis
How it works

The error results from improper permission verification (CWE-280 — Improper Handling of Insufficient Permissions or Privileges). The permission control mechanism in the SDK is weak enough that an attacker or malicious application can gain access to resources and data that should be protected. The vulnerability is remotely exploitable (network vector), does not require user interaction, though it requires high-level permissions (PR:H). The scope of the attack extends beyond the component in which the vulnerability occurs (Scope: Changed).

Impact

An attacker can gain unauthorized access to internal application information, resulting in a breach of confidentiality, integrity, and data availability. The vulnerability may lead to the disclosure of sensitive data stored by the SDK without the user's knowledge and consent.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references published on the OPPO Security page (https://security.oppo.com/en/noticeDetail?notice_only_key=NOTICE-1759867611954552832). It is recommended to update the SDK to the version indicated by the manufacturer as secure.

Who is affected

OPPO Usercenter Credit Software Development Kit — specific versions indicated in the manufacturer's references (OPPO Security Notice page).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Oppo Usercenter Credit Software Development Kit

    APP
    Oppo
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-23247CRITICAL9.8PL ✓same vendor

Command Injection w OPPO Quick Game Engine umożliwiający RCE

CVE-2020-11829CRITICAL9.8PL ✓same vendor

Privilege Escalation w Oppo ColorOS — dynamiczne ładowanie usług SDK backupu

CVE-2020-11830CRITICAL9.8PL ✓same vendor

RCE w Oppo QualityProtect — wykonanie dowolnych poleceń systemowych

CVE-2020-11831CRITICAL9.8PL ✓same vendor

Podatność zapisu dowolnych plików z uprawnieniami systemowymi w Oppo OvoiceManager

CVE-2026-22070HIGH7.1same vendor

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.