ID

VAR-201811-0859


CVE

CVE-2018-7961


TITLE

plural Huawei Information disclosure vulnerability in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2018-014240

DESCRIPTION

There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS verification code, successful exploitation can cause sensitive information leak. plural Huawei Smartphones contain information disclosure vulnerabilities.Information may be obtained. Huawei Emily-AL00A is a smartphone device from China's Huawei. There is a security vulnerability in Huawei Emily-AL00A 8.1.0.167 (C00)

Trust: 2.25

sources: NVD: CVE-2018-7961 // JVNDB: JVNDB-2018-014240 // CNVD: CNVD-2019-33605 // VULHUB: VHN-137993

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-33605

AFFECTED PRODUCTS

vendor:huaweimodel:emily-al00ascope:eqversion:8.1.0.167\(c00\)

Trust: 1.0

vendor:huaweimodel:emily-al00ascope: - version: -

Trust: 0.8

vendor:huaweimodel:emily-al00a 8.1.0.167scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-33605 // JVNDB: JVNDB-2018-014240 // NVD: CVE-2018-7961

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7961
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-7961
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-33605
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-655
value: MEDIUM

Trust: 0.6

VULHUB: VHN-137993
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-7961
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-33605
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-137993
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7961
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-33605 // VULHUB: VHN-137993 // JVNDB: JVNDB-2018-014240 // CNNVD: CNNVD-201811-655 // NVD: CVE-2018-7961

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-137993 // JVNDB: JVNDB-2018-014240 // NVD: CVE-2018-7961

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201811-655

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014240

PATCH

title:huawei-sa-20181121-02-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181121-02-smartphone-en

Trust: 0.8

title:Patch for Huawei Emily-AL00A SMS Verification Code Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/182855

Trust: 0.6

title:Huawei Emily-AL00A Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86975

Trust: 0.6

sources: CNVD: CNVD-2019-33605 // JVNDB: JVNDB-2018-014240 // CNNVD: CNNVD-201811-655

EXTERNAL IDS

db:NVDid:CVE-2018-7961

Trust: 3.1

db:JVNDBid:JVNDB-2018-014240

Trust: 0.8

db:CNNVDid:CNNVD-201811-655

Trust: 0.7

db:CNVDid:CNVD-2019-33605

Trust: 0.6

db:VULHUBid:VHN-137993

Trust: 0.1

sources: CNVD: CNVD-2019-33605 // VULHUB: VHN-137993 // JVNDB: JVNDB-2018-014240 // CNNVD: CNNVD-201811-655 // NVD: CVE-2018-7961

REFERENCES

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20181121-02-smartphone-cn

Trust: 1.2

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181121-02-smartphone-en

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7961

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7961

Trust: 0.8

sources: CNVD: CNVD-2019-33605 // VULHUB: VHN-137993 // JVNDB: JVNDB-2018-014240 // CNNVD: CNNVD-201811-655 // NVD: CVE-2018-7961

SOURCES

db:CNVDid:CNVD-2019-33605
db:VULHUBid:VHN-137993
db:JVNDBid:JVNDB-2018-014240
db:CNNVDid:CNNVD-201811-655
db:NVDid:CVE-2018-7961

LAST UPDATE DATE

2024-11-23T23:04:56.145000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-33605date:2019-09-29T00:00:00
db:VULHUBid:VHN-137993date:2019-02-04T00:00:00
db:JVNDBid:JVNDB-2018-014240date:2019-03-14T00:00:00
db:CNNVDid:CNNVD-201811-655date:2019-02-13T00:00:00
db:NVDid:CVE-2018-7961date:2024-11-21T04:13:01.547

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-33605date:2019-09-29T00:00:00
db:VULHUBid:VHN-137993date:2018-11-27T00:00:00
db:JVNDBid:JVNDB-2018-014240date:2019-03-14T00:00:00
db:CNNVDid:CNNVD-201811-655date:2018-11-23T00:00:00
db:NVDid:CVE-2018-7961date:2018-11-27T22:29:00.430