CVE-2018-7957

Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:victoria-al00_firmware:victoria-al00_8.0.0.336a\(c00\):*:*:*:*:*:*:*
cpe:2.3:h:huawei:victoria-al00:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:13

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-smartphone-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-smartphone-en - Vendor Advisory

Information

Published : 2018-07-31 14:29

Updated : 2024-11-21 04:13


NVD link : CVE-2018-7957

Mitre link : CVE-2018-7957

CVE.ORG link : CVE-2018-7957


JSON object : View

Products Affected

huawei

  • victoria-al00_firmware
  • victoria-al00
CWE
CWE-863

Incorrect Authorization