CVE-2018-7936
Description
Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.
Risk Information
Base Score
4.6
MODERATE
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.027
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 are affected in mate_10_pro_firmware bla-al00b_8.1.0.326(c00) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.1.0.330(c432e6r1p12t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.1.0.321(c636e4r1p14t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.1.0.321(c605e4r1p13t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.0.0.167(c00e87r2p15t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.0.0.161(c432e4r1p11t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.0.0.159(c636e2r1p13t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 9.0.0.159(c185e2r1p13t8) | NCM |
| Vulnerabilities CVE-2018-7934 ,CVE-2018-7936 ,CVE-2018-7989 are affected in mate_10_pro_firmware 8.1.0.326(c00) | NCM |
| Vulnerabilities CVE-2018-7936 are affected in mate_10_pro_firmware bla-l29_8.0.0.145(c432) | NCM |
| CVE-2018-7936 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234