imsservice
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21031 | Med | 0.44 | 6.8 | 0.00 | Sep 3, 2025 | Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs. | ||
| CVE-2025-21027 | Med | 0.33 | 5.1 | 0.00 | Sep 3, 2025 | Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM. | ||
| CVE-2025-21026 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call. | ||
| CVE-2024-20899 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20897 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2022-39856 | Med | 0.26 | 4.0 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information. | ||
| CVE-2022-25833 | Low | 0.21 | 3.3 | 0.00 | Apr 11, 2022 | Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission. |
- risk 0.44cvss 6.8epss 0.00
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
- risk 0.33cvss 5.1epss 0.00
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.
- risk 0.21cvss 3.3epss 0.00
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.