First published: Tue Oct 09 2018(Updated: )
There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special steps by exploit this vulnerability. As a result, the FRP function is bypassed.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Westerndigital My Cloud | <8.1.2.303 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7928 is a security vulnerability that could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP on some Huawei smartphones.
CVE-2018-7928 affects Huawei smartphones with the MyCloud APP versions before 8.1.2.303 installed.
CVE-2018-7928 has a severity rating of medium, with a CVSS score of 4.6.
An attacker can exploit CVE-2018-7928 by replacing the old account with a new one when re-configuring the mobile phone using the FRP function.
To fix CVE-2018-7928, update the MyCloud APP to version 8.1.2.303 or higher on Huawei smartphones.