Vulnerability Description
There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special steps by exploit this vulnerability. As a result, the FRP function is bypassed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | My Cloud | < 8.1.2.303 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180930-01-mycloudVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180930-01-mycloudVendor Advisory
FAQ
What is CVE-2018-7928?
CVE-2018-7928 is a vulnerability with a CVSS score of 4.6 (MEDIUM). There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configu...
How severe is CVE-2018-7928?
CVE-2018-7928 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7928?
Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud.