First published: Tue Sep 04 2018(Updated: )
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can read some hardware serial number, which may cause sensitive information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <victoria-al00ac00b217 | |
Huawei P10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7938 is a vulnerability found in P10 Huawei smartphones with versions before Victoria-AL00AC00B217 that allows an attacker to read hardware serial numbers through a malicious application.
CVE-2018-7938 has a severity value of 3.3, which is categorized as medium.
CVE-2018-7938 works by tricking a user into installing a malicious application on their P10 Huawei smartphone, which then reads hardware serial numbers without proper permission validation.
Only P10 Huawei smartphones with versions before Victoria-AL00AC00B217 are affected by CVE-2018-7938.
To protect your Huawei P10 from CVE-2018-7938, ensure that you have installed the Victoria-AL00AC00B217 version of the firmware.