PT-2019-9081 · Suntek+4 · Com.Suntek.Mway.Rcs.App.Service+4
Published
2019-04-25
·
Updated
2019-05-02
·
CVE-2018-14990
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Coolpad Defiant version 7.1.1
ZTE ZMAX Pro version 6.0.1
T-Mobile Revvl Plus version 7.1.1
com.suntek.mway.rcs.app.service versions RCS sdk M native 20161008 01 through RCS sdk M native 20170406 01
com.rcs.gsma.na.sdk version RCS SDK 20170804 01
Description
The pre-installed Rich Communication Services (RCS) app on certain devices contains an exported broadcast receiver app component, allowing any co-located app to send text messages with attacker-controlled number and body. This can be done by a zero-permission app, and the app cannot be disabled by the user. Additionally, a separate issue in the app allows a zero-permission app to delete text messages, potentially removing evidence of the sent messages.
Recommendations
For Coolpad Defiant version 7.1.1, consider disabling the
com.suntek.mway.rcs.app.test.TestReceiver broadcast receiver app component as a temporary workaround.
For ZTE ZMAX Pro version 6.0.1, restrict access to the com.suntek.mway.rcs.app.service package to minimize the risk of exploitation.
For T-Mobile Revvl Plus version 7.1.1, avoid using the com.rcs.gsma.na.test.TestReceiver broadcast receiver app component until the issue is resolved.
For com.suntek.mway.rcs.app.service versions RCS sdk M native 20161008 01 through RCS sdk M native 20170406 01, and com.rcs.gsma.na.sdk version RCS SDK 20170804 01, at the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coolpad Defiant
T-Mobile Revvl Plus
Zte Zmax Pro
Com.Rcs.Gsma.Na.Sdk
Com.Suntek.Mway.Rcs.App.Service