Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7901

Опубликовано: 30 апр. 2018
Источник: nvd
CVSS3: 4.4
CVSS2: 5.8
EPSS Низкий

Описание

RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the application connects with RCS for the first time, it needs user to manually click to agree. In addition, the attacker needs to obtain the key that RCS uses to authenticate the application. Successful exploitation may cause the attacker to control keyboard remotely.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:*
Версия до 8.0.0.129 (исключая)
cpe:2.3:h:huawei:alp-al00b:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:*
Версия до 8.0.0.129 (исключая)
cpe:2.3:h:huawei:bla-al00b:-:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00081
Низкий

4.4 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.4
github
больше 3 лет назад

RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the application connects with RCS for the first time, it needs user to manually click to agree. In addition, the attacker needs to obtain the key that RCS uses to authenticate the application. Successful exploitation may cause the attacker to control keyboard remotely.

EPSS

Процентиль: 24%
0.00081
Низкий

4.4 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo