ID

VAR-201808-1005


CVE

CVE-2018-6597


TITLE

Alcatel A30 Vulnerabilities related to authorization, authority, and access control in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-010074

DESCRIPTION

The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidden privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to obtain a root shell via ADB. Modifying the read-only properties by an app as the system user creates a UNIX domain socket named factory_test that will execute commands as the root user by processes that have privilege to access it (as per the SELinux rules that the vendor controls). Alcatel A30 Devices have vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Alcatel A30 is a smartphone product. A security vulnerability exists in Alcatel A30 (with TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys). An attacker can exploit this vulnerability to execute commands as the root user

Trust: 1.71

sources: NVD: CVE-2018-6597 // JVNDB: JVNDB-2018-010074 // VULHUB: VHN-136629

AFFECTED PRODUCTS

vendor:alcatelmodel:a30scope:eqversion:7.0

Trust: 1.6

vendor:tcl communication holdings tcl communicationmodel:alcatel a30scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-010074 // CNNVD: CNNVD-201808-917 // NVD: CVE-2018-6597

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-6597
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-6597
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201808-917
value: MEDIUM

Trust: 0.6

VULHUB: VHN-136629
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-6597
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-136629
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-6597
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-136629 // JVNDB: JVNDB-2018-010074 // CNNVD: CNNVD-201808-917 // NVD: CVE-2018-6597

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-136629 // JVNDB: JVNDB-2018-010074 // NVD: CVE-2018-6597

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201808-917

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201808-917

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010074

PATCH

title:Top Pageurl:https://us.alcatelmobile.com/

Trust: 0.8

sources: JVNDB: JVNDB-2018-010074

EXTERNAL IDS

db:NVDid:CVE-2018-6597

Trust: 2.5

db:JVNDBid:JVNDB-2018-010074

Trust: 0.8

db:CNNVDid:CNNVD-201808-917

Trust: 0.7

db:VULHUBid:VHN-136629

Trust: 0.1

sources: VULHUB: VHN-136629 // JVNDB: JVNDB-2018-010074 // CNNVD: CNNVD-201808-917 // NVD: CVE-2018-6597

REFERENCES

url:https://www.kryptowire.com/portal/android-firmware-defcon-2018/

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-6597

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-6597

Trust: 0.8

sources: VULHUB: VHN-136629 // JVNDB: JVNDB-2018-010074 // CNNVD: CNNVD-201808-917 // NVD: CVE-2018-6597

SOURCES

db:VULHUBid:VHN-136629
db:JVNDBid:JVNDB-2018-010074
db:CNNVDid:CNNVD-201808-917
db:NVDid:CVE-2018-6597

LAST UPDATE DATE

2024-11-23T22:21:56.632000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-136629date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-010074date:2018-12-05T00:00:00
db:CNNVDid:CNNVD-201808-917date:2019-10-23T00:00:00
db:NVDid:CVE-2018-6597date:2024-11-21T04:10:58.190

SOURCES RELEASE DATE

db:VULHUBid:VHN-136629date:2018-08-29T00:00:00
db:JVNDBid:JVNDB-2018-010074date:2018-12-05T00:00:00
db:CNNVDid:CNNVD-201808-917date:2018-08-30T00:00:00
db:NVDid:CVE-2018-6597date:2018-08-29T19:29:01.047