CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
Percentile
25.8%
There is an improper authentication vulnerability on smartphones. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of operations. Successful exploit could allow the attacker to use the application which is locked. (Vulnerability ID: HWPSIRT-2018-06006)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2018-7989.
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181010-01-applock-en
Vendor | Product | Version | CPE |
---|---|---|---|
huawei | alp-al00b_firmware | * | cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:* |
huawei | alp-tl00b_firmware | * | cpe:2.3:o:huawei:alp-tl00b_firmware:*:*:*:*:*:*:*:* |
huawei | anne-al00_firmware | * | cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:* |
huawei | atomu-l41_firmware | * | cpe:2.3:o:huawei:atomu-l41_firmware:*:*:*:*:*:*:*:* |
huawei | jenny-al10b_firmware | * | cpe:2.3:o:huawei:jenny-al10b_firmware:*:*:*:*:*:*:*:* |
huawei | florida-al20b_firmware | * | cpe:2.3:o:huawei:florida-al20b_firmware:*:*:*:*:*:*:*:* |
huawei | cornell-l29a_firmware | * | cpe:2.3:o:huawei:cornell-l29a_firmware:*:*:*:*:*:*:*:* |
huawei | bla-al00b_firmware | * | cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:* |
huawei | bla-tl00b_firmware | * | cpe:2.3:o:huawei:bla-tl00b_firmware:*:*:*:*:*:*:*:* |
huawei | berkeley-tl10_firmware | * | cpe:2.3:o:huawei:berkeley-tl10_firmware:*:*:*:*:*:*:*:* |
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
Percentile
25.8%