Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-7910


Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8.0.0.137(C432), BLA-L29C 8.0.0.129(C432), 8.0.0.137(C432) have an authentication bypass vulnerability. When the attacker obtains the user's smartphone, the vulnerability can be used to replace the start-up program so that the attacker can obtain the information in the smartphone and achieve the purpose of controlling the smartphone.


Published

2018-11-13T19:29:00.400

Last Modified

2024-11-21T04:12:57.327

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei alp-al00b_firmware 8.0.0.1.18d\(c00\) Yes
Hardware huawei alp-al00b - No
Operating System huawei alp-tl00b_firmware 8.0.0.1.18d\(c01\) Yes
Hardware huawei alp-tl00b - No
Operating System huawei bla-al00b_firmware 8.0.0.1.18d\(c00\) Yes
Hardware huawei bla-al00b - No
Operating System huawei bla-l09c_firmware 8.0.0.127\(c432\) Yes
Operating System huawei bla-l09c_firmware 8.0.0.128\(c432\) Yes
Operating System huawei bla-l09c_firmware 8.0.0.137\(c432\) Yes
Hardware huawei bla-l09c - No
Operating System huawei bla-l29c_firmware 8.0.0.127\(c432\) Yes
Operating System huawei bla-l29c_firmware 8.0.0.137\(c432\) Yes
Hardware huawei bla-l29c - No

References