CVE-2018-7957
Summary
| CVE | CVE-2018-7957 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-31 14:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Victoria-al00 | - | All | All | All |
| Hardware | Huawei | Victoria-al00 | - | All | All | All |
| Operating System | Huawei | Victoria-al00 Firmware | victoria-al00_8.0.0.336a(c00) | All | All | All |
| Operating System | Huawei | Victoria-al00 Firmware | victoria-al00_8.0.0.336a\(c00\) | All | All | All |
| Operating System | Huawei | Victoria-al00 Firmware | victoria-al00_8.0.0.336a\(c00\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Information Leakage Vulnerability on Huawei Smart Phone | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.