4.9
CVE-2018-7911
- EPSS 0.03%
- Published 23.10.2018 14:29:04
- Last modified 21.11.2024 04:12:57
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2, BLA-TL00B 8.0.0.113(SP7C01), 8.0.0.118(C01), 8.0.0.120(SP2C01), 8.0.0.125(SP1C01), 8.0.0.125(SP2C01), 8.0.0.125(SP3C01), 8.0.0.126(SP2C01), 8.0.0.126(SP5C01), 8.0.0.127(SP1C01), 8.0.0.128(SP2C01), 8.0.0.129(SP2C01), Charlotte-AL00A 8.1.0.105(SP7C00), 8.1.0.106(SP3C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP3C00), 8.1.0.108(SP6C00), 8.1.0.109(SP2C00), Emily-AL00A 8.1.0.105(SP6C00), 8.1.0.106(SP2C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP2C00), 8.1.0.108(SP6C00), 8.1.0.109(SP5C00) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Gaode Map and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Alp-al00b Firmware Version8.0.0.106(c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp3c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.113(sp7c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.118(c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.120(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.125(sp1c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.125(sp3c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.126(sp2c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.126(sp5c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.127(sp1c00)
Huawei ≫ Alp-al00b Firmware Version8.0.0.128(sp2c00)
Huawei ≫ Alp-al00b-rsc Firmware Version1.0.0.2
Huawei ≫ Bla-tl00b Firmware Version8.0.0.113(sp7c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.118(c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.120(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp1c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.125(sp3c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.126(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.126(sp5c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.127(sp1c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.128(sp2c01)
Huawei ≫ Bla-tl00b Firmware Version8.0.0.129(sp2c01)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.105(sp7c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.106(sp3c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.107(sp5c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.107(sp7c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.108(sp3c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.108(sp6c00)
Huawei ≫ Charlotte-al00a Firmware Version8.1.0.109(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.105(sp6c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.106(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.107(sp5c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.107(sp7c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.108(sp2c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.108(sp6c00)
Huawei ≫ Emily-al00a Firmware Version8.1.0.109(sp5c00)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.045 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 0.9 | 3.6 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:C/A:N
|