Vulnerability Intelligence Report
CVE-2018-7961
There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS verification code, successful exploitation can cause sensitive information leak.
No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
EPSS Probability:0.90%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Huawei Technologies Co., Ltd. | Emily-AL00A | 8.1.0.167(C00) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.900%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Huawei Technologies · Vendor · China |
| Reserved | 2018-03-09T00:00:00 |
| Published | 2018-11-27T22:00:00 |
| Patch Date | 2018-11-21 |
| Last Updated | 2024-08-05T06:37:59 |
Community Chatter & Buzz