4.9
CVE-2018-7911
- EPSS 0.03%
- Veröffentlicht 23.10.2018 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:12:57
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2, BLA-TL00B 8.0.0.113(SP7C01), 8.0.0.118(C01), 8.0.0.120(SP2C01), 8.0.0.125(SP1C01), 8.0.0.125(SP2C01), 8.0.0.125(SP3C01), 8.0.0.126(SP2C01), 8.0.0.126(SP5C01), 8.0.0.127(SP1C01), 8.0.0.128(SP2C01), 8.0.0.129(SP2C01), Charlotte-AL00A 8.1.0.105(SP7C00), 8.1.0.106(SP3C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP3C00), 8.1.0.108(SP6C00), 8.1.0.109(SP2C00), Emily-AL00A 8.1.0.105(SP6C00), 8.1.0.106(SP2C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP2C00), 8.1.0.108(SP6C00), 8.1.0.109(SP5C00) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Gaode Map and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Alp-al00b Firmware Version8.0.0.106(c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp3c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp7c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.118(c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.120(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.125(sp1c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.125(sp3c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.126(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.126(sp5c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.127(sp1c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.128(sp2c00)
Huawei ≫ Alp-al00b-rsc Firmware Version1.0.0.2
Huawei ≫ Bla-tl00b Firmware Version8.0.0.113(sp7c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.118(c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.120(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp1c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp3c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.126(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.126(sp5c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.127(sp1c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.128(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.129(sp2c01)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.105(sp7c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.106(sp3c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.107(sp5c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.107(sp7c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.108(sp3c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.108(sp6c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.109(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.105(sp6c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.106(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.107(sp5c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.107(sp7c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.108(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.108(sp6c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.109(sp5c00)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.045 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 0.9 | 3.6 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:C/A:N
|