Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20181010-01-APPLOCK
HistoryOct 10, 2018 - 12:00 a.m.

Security Advisory - Improper Authentication Vulnerability on Smartphones

2018-10-1000:00:00
Huawei Technologies
www.huawei.com
21

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

25.8%

There is an improper authentication vulnerability on smartphones. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of operations. Successful exploit could allow the attacker to use the application which is locked. (Vulnerability ID: HWPSIRT-2018-06006)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2018-7989.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181010-01-applock-en

Affected configurations

Vulners
Node
huaweialp-al00b_firmwareRange<8.1.0.326
OR
huaweialp-tl00b_firmwareRange<8.1.0.326
OR
huaweianne-al00_firmwareRange<8.0.0.165
OR
huaweiatomu-l41_firmwareRange<8.0.0.186
OR
huaweijenny-al10b_firmwareRange<8.0.0.186
OR
huaweiflorida-al20b_firmwareRange<8.0.0.186
OR
huaweicornell-l29a_firmwareRange<8.0.0.140
OR
huaweiatomu-l41_firmwareRange<8.0.0.140
OR
huaweibla-al00b_firmwareRange<8.1.0.326
OR
huaweibla-tl00b_firmwareRange<8.1.0.326
OR
huaweiberkeley-tl10_firmwareRange<8.0.0.192
OR
huaweiduke-l09_firmwareRange<8.0.0.366
OR
huaweiduke-l09_firmwareRange<8.0.0.368
OR
huaweiduke-l09_firmwareRange<8.0.0.369
OR
huaweifigo-al00a_firmwareRange<8.0.0.173
OR
huaweifigo-tl10b_firmwareRange<8.0.0.176
OR
huaweifigo-l31_firmwareRange<8.0.0.124
OR
huaweifigo-l31_firmwareRange<8.0.0.130
OR
huaweifigo-l31_firmwareRange<8.0.0.133
OR
huaweifigo-l31_firmwareRange<8.0.0.136
OR
huaweifigo-l31_firmwareRange<8.0.0.148
OR
huaweifigo-tl10b_firmwareRange<8.0.0.173
OR
huaweijenny-al10b_firmwareRange<8.0.0.168
OR
huaweiflorida-tl10b_firmwareRange<8.0.0.168
OR
huaweiy6_prime_2018_firmwareRange<8.0.0.140
OR
huaweinova_3e_firmwareRange<8.0.0.142
OR
huaweijimmy-al00a_firmwareRange<Jimmy-AL00AC00B172
OR
huaweidura-tl00a_firmwareRange<Jimmy-TL00AC01B172
OR
huaweileland-al00a_firmwareRange<8.0.0.178
OR
huaweileland-l22c_firmwareRange<8.0.0.185
OR
huaweileland-l42a_firmwareRange<8.0.0.175
OR
huaweileland-l42c_firmwareRange<8.0.0.175
OR
huaweileland-tl10b_firmwareRange<8.0.0.178
OR
huaweileland-tl10c_firmwareRange<8.0.0.178
OR
huaweilelandp-al00c_firmwareRange<8.0.0.123
OR
huaweilon-al00b_firmwareRange<8.0.0.211
OR
huaweivicky-al00c_firmwareRange<8.0.0.211
OR
huaweineo-al00d_firmwareRange<8.0.0.211
OR
huaweiaslan-al10_firmwareRange<8.0.0.211
OR
huaweilondon-al40ind_firmwareRange<8.0.0.211
OR
huaweilondon-al40ind_firmwareRange<8.0.0.150
OR
huaweilondon-al40ind_firmwareRange<8.0.0.211
OR
huaweilondon-al40ind_firmwareRange<8.0.0.150
OR
huaweieva-l29_firmwareRange<8.0.0.132
OR
huaweiemily-tl00b_firmwareRange<8.0.0.211
OR
huaweiharry-tl00c_firmwareRange<8.0.0.211
OR
huaweitoronto-tl10_firmwareRange<8.0.0.211
OR
huaweilondon-al40ind_firmwareRange<8.0.0.211
OR
huaweistanford-al00_firmwareRange<8.0.0.355
OR
huaweitoronto-al00_firmwareRange<Toronto-AL00C00B225
OR
huaweitoronto-al00a_firmwareRange<Toronto-AL00AC00B225
OR
huaweitoronto-tl10_firmwareRange<Toronto-TL10C01B225
VendorProductVersionCPE
huaweialp-al00b_firmware*cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:*
huaweialp-tl00b_firmware*cpe:2.3:o:huawei:alp-tl00b_firmware:*:*:*:*:*:*:*:*
huaweianne-al00_firmware*cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:*
huaweiatomu-l41_firmware*cpe:2.3:o:huawei:atomu-l41_firmware:*:*:*:*:*:*:*:*
huaweijenny-al10b_firmware*cpe:2.3:o:huawei:jenny-al10b_firmware:*:*:*:*:*:*:*:*
huaweiflorida-al20b_firmware*cpe:2.3:o:huawei:florida-al20b_firmware:*:*:*:*:*:*:*:*
huaweicornell-l29a_firmware*cpe:2.3:o:huawei:cornell-l29a_firmware:*:*:*:*:*:*:*:*
huaweibla-al00b_firmware*cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:*
huaweibla-tl00b_firmware*cpe:2.3:o:huawei:bla-tl00b_firmware:*:*:*:*:*:*:*:*
huaweiberkeley-tl10_firmware*cpe:2.3:o:huawei:berkeley-tl10_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 381

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

25.8%

Related for HUAWEI-SA-20181010-01-APPLOCK