PT-2018-18361 · Huawei · Huawei Mate 10
Rongwei Ji
·
Published
2018-09-18
·
Updated
2019-10-03
·
CVE-2018-7991
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Huawei Mate10 versions earlier than 8.0.0.110(C00)
Description:
The issue concerns a Factory Reset Protection (FRP) bypass. It arises because the system does not sufficiently verify permissions. An attacker can exploit this by connecting the smartphone to a computer using a data cable and performing specific operations. This could allow the attacker to bypass FRP protection and access the system setting page.
Recommendations:
For versions earlier than 8.0.0.110(C00), update to version 8.0.0.110(C00) or later to resolve the issue. As a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei Mate 10