CVE-2018-7930: Infoleak
The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vulnerability due to insufficient validation on data transfer requests. When an affected mobile phone sends files to an attacker's mobile phone using the NFC function, the attacker can obtain arbitrary files from the mobile phone, causing information leaks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Huawei Mate 9 NFC moduleto a version that resolves this vulnerability.Fixed in MHA-L29B 8.0.0.366(C567) - Compensating control
If you must keep using an affected Huawei Mate 9 (NFC module versions before MHA-L29B 8.0.0.366(C567)), avoid sending files over NFC to other devices to prevent attackers from obtaining arbitrary files via NFC data transfer requests.
Event History
Frequently Asked Questions
What is CVE-2018-7930?
CVE-2018-7930 is an information leak vulnerability in the Near Field Communication (NFC) module of Huawei Mate 9 mobile phones prior to version MHA-L29B 8.0.0.366(C567).
How does CVE-2018-7930 occur?
CVE-2018-7930 occurs due to insufficient validation on data transfer requests when an affected Huawei Mate 9 mobile phone sends files to an attacker's mobile phone using NFC.
What is the severity of CVE-2018-7930?
CVE-2018-7930 has a severity rating of 5.7, which is considered medium.
Which software versions are affected by CVE-2018-7930?
The Huawei Mate 9 mobile phones with firmware versions prior to MHA-L29B 8.0.0.366(C567) are affected by CVE-2018-7930.
How can CVE-2018-7930 be fixed?
To fix CVE-2018-7930, users should update their Huawei Mate 9 mobile phones to version MHA-L29B 8.0.0.366(C567) or later.