CVE Vulnerabilities

CVE-2016-7991

Published: Oct 31, 2016 | Modified: Dec 02, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:C/A:N
RedHat/V2
RedHat/V3
Ubuntu

On Samsung Galaxy S4 through S7 devices, the omacp app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.

Affected Software

Name Vendor Start Version End Version
Android Google 4.2.2 (including) 4.2.2 (including)
Android Google 4.3 (including) 4.3 (including)
Android Google 4.3.1 (including) 4.3.1 (including)
Android Google 4.4 (including) 4.4 (including)
Android Google 4.4.1 (including) 4.4.1 (including)
Android Google 4.4.2 (including) 4.4.2 (including)
Android Google 4.4.3 (including) 4.4.3 (including)
Android Google 4.4.4 (including) 4.4.4 (including)
Android Google 5.0 (including) 5.0 (including)
Android Google 5.0.1 (including) 5.0.1 (including)
Android Google 5.0.2 (including) 5.0.2 (including)
Android Google 5.1 (including) 5.1 (including)
Android Google 5.1.0 (including) 5.1.0 (including)
Android Google 5.1.1 (including) 5.1.1 (including)
Android Google 6.0 (including) 6.0 (including)
Android Google 6.0.1 (including) 6.0.1 (including)

References