CVE-2018-7923: Input Validation
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the application may modify the specific data to exploit the vulnerability. Successful exploit could allow the attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7923?
CVE-2018-7923 is a vulnerability that affects Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432).
How severe is CVE-2018-7923?
CVE-2018-7923 has a severity rating of 7.8 (critical).
How does CVE-2018-7923 affect Huawei ALP-L09 smart phones?
CVE-2018-7923 allows an attacker to modify specific data on Huawei ALP-L09 smart phones with vulnerable versions before ALP-L09 8.0.0.150(C432) by tricking a user with root privilege to install a crafted application.
What software versions are affected by CVE-2018-7923?
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) are affected by CVE-2018-7923.
How can I fix CVE-2018-7923?
To fix CVE-2018-7923, update your Huawei ALP-L09 smart phone to version ALP-L09 8.0.0.150(C432) or later.