CVE-2018-7923
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the application may modify the specific data to exploit the vulnerability. Successful exploit could allow the attacker to execute arbitrary code.
Los smartphones Huawei ALP-L09 en versiones anteriores a la ALP-L09 8.0.0.150(C432) tienen una vulnerabilidad de validación de entradas insuficiente debido a la falta de comprobación de parámetros. Un atacante engaña al usuario que tiene privilegios root para que instale una aplicación manipulada, que podría modificar los datos específicos para explotar la vulnerabilidad. Su explotación con éxito podría permitir que el atacante ejecute código arbitrario.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-09-12 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180911-01-smartphone-en | 2018-11-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Alp-l09 Firmware Search vendor "Huawei" for product "Alp-l09 Firmware" | < 8.0.0.150\(c432\) Search vendor "Huawei" for product "Alp-l09 Firmware" and version " < 8.0.0.150\(c432\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Alp-l09 Search vendor "Huawei" for product "Alp-l09" | - | - |
Safe
|