First published: Mon Apr 30 2018(Updated: )
RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the application connects with RCS for the first time, it needs user to manually click to agree. In addition, the attacker needs to obtain the key that RCS uses to authenticate the application. Successful exploitation may cause the attacker to control keyboard remotely.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Alp-al00b Firmware | <8.0.0.129 | |
Huawei ALP-AL00B | ||
Huawei Bla-al00b Firmware | <8.0.0.129 | |
Huawei Bla-al00b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7901.
The severity of CVE-2018-7901 is medium with a severity value of 4.4.
Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129 and BLA-AL00B smart phones with software versions earlier than 8.0.0.129 are affected by CVE-2018-7901.
An attacker can trick a user to install a malicious application that connects with RCS to exploit CVE-2018-7901.
You can find more information about CVE-2018-7901 on the Huawei website: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180425-01-rcs-en