CVE-2018-7938
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can read some hardware serial number, which may cause sensitive information leak.
Los smartphones Huawei P10 con software en versiones anteriores a Victoria-AL00AC00B217 tienen una vulnerabilidad de filtrado de información debido a la falta de validación de permisos. Un atacante podría engañar a un usuario para que instale una aplicación maliciosa en el smartphone que pueda leer el número de serie del hardware, lo que podría causar una filtración de información sensible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-09-04 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180827-01-smartphone-en | 2018-10-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | P10 Firmware Search vendor "Huawei" for product "P10 Firmware" | < victoria-al00ac00b217 Search vendor "Huawei" for product "P10 Firmware" and version " < victoria-al00ac00b217" | - |
Affected
| in | Huawei Search vendor "Huawei" | P10 Search vendor "Huawei" for product "P10" | - | - |
Safe
|