CVE Vulnerabilities

CVE-2016-7991

Published: Oct 31, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:C/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

On Samsung Galaxy S4 through S7 devices, the omacp app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.2.2 (including)4.2.2 (including)
AndroidGoogle4.3 (including)4.3 (including)
AndroidGoogle4.3.1 (including)4.3.1 (including)
AndroidGoogle4.4 (including)4.4 (including)
AndroidGoogle4.4.1 (including)4.4.1 (including)
AndroidGoogle4.4.2 (including)4.4.2 (including)
AndroidGoogle4.4.3 (including)4.4.3 (including)
AndroidGoogle4.4.4 (including)4.4.4 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.0.2 (including)5.0.2 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle5.1.1 (including)5.1.1 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)

References