First published: Tue Nov 27 2018(Updated: )
There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS verification code, successful exploitation can cause sensitive information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Emily-al00a Firmware | =8.1.0.167\(c00\) | |
Huawei Emily-al00a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7961 is a smart SMS verification code vulnerability in some Huawei smart phones.
An attacker can exploit CVE-2018-7961 by tricking a user to access a malicious website or app and register, causing sensitive information to leak.
CVE-2018-7961 affects Huawei smart phones with the following firmware version: 8.1.0.167(c00).
No, Huawei Emily-al00a is not vulnerable to CVE-2018-7961.
CVE-2018-7961 has a severity value of 6.5, which is considered medium.
To fix CVE-2018-7961, it is recommended to update the affected Huawei smart phone to a firmware version that addresses the vulnerability.