Vulnerability Description
On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 4.2.2 | |
| Samsung | Galaxy S4 | - |
| Samsung | Galaxy S4 Mini | - |
| Samsung | Galaxy S5 | - |
| Samsung | Galaxy S6 | - |
| Samsung | Galaxy S7 | - |
Related Weaknesses (CWE)
References
- http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016Vendor Advisory
- http://www.securityfocus.com/bid/94088Third Party AdvisoryVDB Entry
- http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016Vendor Advisory
- http://www.securityfocus.com/bid/94088Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-7991?
CVE-2016-7991 is a vulnerability with a CVSS score of 7.5 (HIGH). On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and h...
How severe is CVE-2016-7991?
CVE-2016-7991 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7991?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Samsung Galaxy S4, Samsung Galaxy S4 Mini, Samsung Galaxy S5, Samsung Galaxy S6.