CVE-2018-7936

UnknownEPSS 0.24%

Last modified

CVE-2018-7936 is a vulnerability of currently unknown severity. Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.

Metrics

EPSS Probability
0.24%

14.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HuaweiMate 10 Pro Firmware< bla-l29_8.0.0.148\(c432\)

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7936?
Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.
How severe is CVE-2018-7936?
Severity scoring for CVE-2018-7936 is pending analysis. The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7936?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7936?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST