Input Validation Flaw in Huawei Smartphones Allows Code Execution
CVE-2018-7923

7.8HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
12 September 2018

Summary

Huawei ALP-L09 smartphones running on versions earlier than 8.0.0.150(C432) are affected by a vulnerability stemming from insufficient input validation. An attacker could exploit this flaw by tricking a user with root privileges into installing a malicious application. Upon installation, the crafted application could potentially modify specific data, enabling the attacker to execute arbitrary code on the device. This security issue warrants attention from users to safeguard against unauthorized access and data manipulation.

Affected Version(s)

ALP-L09 Versions earlier than ALP-L09 8.0.0.150(C432)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.