CVE-2018-15004
Last modified
CVE-2018-15004 is a vulnerability of currently unknown severity. The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that contains an exported service app component named com.qualcomm.qti.modemtestmode.MbnTestService that allows any app on the device to set certain system properties as the com.android.phone user. When an app sets the persist.service.logr.enable system property to a value of 1, an app with a package name of com.yulong.logredirect (versionCode=20160622, versionName=5.25_20160622_01) will start writing the system-wide logcat log, kernel log, and a tcpdump network traffic capture to external storage. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (versionCode=24, versionName=7.0) that contains an exported service app component named com.qualcomm.qti.modemtestmode.MbnTestService that allows any app on the device to set certain system properties as the com.android.phone user. When an app sets the persist.service.logr.enable system property to a value of 1, an app with a package name of com.yulong.logredirect (versionCode=20160622, versionName=5.25_20160622_01) will start writing the system-wide logcat log, kernel log, and a tcpdump network traffic capture to external storage. Furthermore, on the Coolpad Canvas device, the com.android.phone app writes the destination phone number and body of the text message for outgoing text messages. A notification when logging can be avoided if the log is enabled after device startup and disabled prior to device shutdown by setting the system properties using the exported interface of the com.qualcomm.qti.modemtestmode app. Any app with the READ_EXTERNAL_STORAGE permission can access the log files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Coolpad | Canvas Firmware | 7.0 |
References
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Exploit, Third Party Advisory
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15004?
How severe is CVE-2018-15004?
How do I fix CVE-2018-15004?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14998The Leagoo P1 Android device with a build fingerprint of sp7…
- CVE-2018-14999The Leagoo P1 device with a build fingerprint of sp7731c_1h1…
- CVE-2018-15000The Vivo V7 Android device with a build fingerprint of vivo/…
- CVE-2018-15001The Vivo V7 Android device with a build fingerprint of vivo/…
- CVE-2018-15002The Vivo V7 device with a build fingerprint of vivo/1718/171…
- CVE-2018-15003The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/09…
- CVE-2018-15005The ZTE ZMAX Champ Android device with a build fingerprint o…
- CVE-2018-15006The ZTE ZMAX Champ Android device with a build fingerprint o…
- CVE-2018-15007The Sky Elite 6.0L+ Android device with a build fingerprint …
- CVE-2018-1501IBM Security Guardium 10.5, 10.6, and 11.0 could allow an un…7.5
- CVE-2018-1502IBM Content Manager Enterprise Edition Resource Manager 8.4.…
- CVE-2018-1503IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely au…4.3
Are you affected by CVE-2018-15004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
