PT-2018-18324 · Huawei · Alp-L09

Publicado

2018-09-12

·

Atualizado

2018-11-20

·

CVE-2018-7923

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Huawei ALP-L09 versions prior to 8.0.0.150(C432)
Description: The issue is due to insufficient input validation resulting from a lack of parameter checks. An attacker can trick a user with root privileges into installing a crafted application, which may modify specific data to exploit this issue. Successful exploitation could allow the attacker to execute arbitrary code.
Recommendations: For versions prior to 8.0.0.150(C432), update to version 8.0.0.150(C432) or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7923

Produtos afetados

Alp-L09