Vulnerability Description
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some specific operations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mate 9 Firmware | < 8.0.0.129\(sp2c00\) |
| Huawei | Mate 9 | - |
| Huawei | Mate 9 Pro Firmware | < 8.0.0.129\(sp2c01\) |
| Huawei | Mate 9 Pro | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180509-01-mobile-Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180509-01-mobile-Vendor Advisory
FAQ
What is CVE-2018-7940?
CVE-2018-7940 is a vulnerability with a CVSS score of 6.2 (MEDIUM). Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high ...
How severe is CVE-2018-7940?
CVE-2018-7940 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7940?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 9 Firmware, Huawei Mate 9, Huawei Mate 9 Pro Firmware, Huawei Mate 9 Pro.