CVE-2018-7940: Medium severity Huawei Mate 9 Firmware vulnerability
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some specific operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Huawei Mate 10to a version that resolves this vulnerability.Fixed in 8.0.0.129(SP2C00) - Upgrade
Upgrade
Huawei Mate 10 Proto a version that resolves this vulnerability.Fixed in 8.0.0.129(SP2C01)
Event History
Frequently Asked Questions
What is the vulnerability ID for this Huawei smart phone vulnerability?
The vulnerability ID for this Huawei smart phone vulnerability is CVE-2018-7940.
Which Huawei smart phones are affected by this vulnerability?
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) are affected by this vulnerability.
What is the severity of CVE-2018-7940?
The severity of CVE-2018-7940 is high.
How can an attacker exploit this vulnerability?
An attacker with high privilege can obtain the smart phone and bypass the activation function by performing specific operations.
Is there a fix available for this vulnerability?
Please refer to the Huawei security advisory for information on available fixes.