Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-smartphone-en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2018-07-31 14:29
Updated : 2019-10-03 00:03
NVD link : CVE-2018-7957
Mitre link : CVE-2018-7957
CVE.ORG link : CVE-2018-7957
JSON object : View
Products Affected
huawei
- victoria-al00
- victoria-al00_firmware
CWE
CWE-863
Incorrect Authorization