Description
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95915
Vendor Advisory x_refsource_confirm
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-vmall-en
Scores
CVSS v3
3.3
EPSS
0.0007
EPSS Percentile
21.5%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-275
Status
published
Products (2)
huawei/vmall
< 1.5.2.0
Huawei Technologies Co., Ltd./HwVmall
Earlier than HwVmall 1.5.2.0 versions
Published
Nov 22, 2017
Tracked Since
Feb 18, 2026