Input Validation Flaw in Huawei Smartphones Allows Code Execution
CVE-2018-7923
7.8HIGH
Summary
Huawei ALP-L09 smartphones running on versions earlier than 8.0.0.150(C432) are affected by a vulnerability stemming from insufficient input validation. An attacker could exploit this flaw by tricking a user with root privileges into installing a malicious application. Upon installation, the crafted application could potentially modify specific data, enabling the attacker to execute arbitrary code on the device. This security issue warrants attention from users to safeguard against unauthorized access and data manipulation.
Affected Version(s)
ALP-L09 Versions earlier than ALP-L09 8.0.0.150(C432)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved