Factory Reset Protection Bypass in Huawei Smartphones
CVE-2018-7939

4.6MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
12 September 2018

Summary

Huawei smartphones including models G9 Lite, Honor 5A, Honor 6X, and Honor 8 are susceptible to a bypass of the Factory Reset Protection (FRP) feature. This vulnerability occurs when an attacker exploits the boot wizard configuration by enabling the talkback function during re-setup. Consequently, the FRP mechanism can be disabled, allowing unauthorized access to the device. Users of the affected models and versions should take immediate steps to update their devices to mitigate the risks associated with this vulnerability.

Affected Version(s)

G9 Lite, Honor 5A, Honor 6X, Honor 8 The versions before VNS-L53C605B120CUSTC605D103, The versions before CAM-L03C605B143CUSTC605D008, The versions before CAM-L21C10B145, The versions before CAM-L21C185B156, The versions before CAM-L21C223B133, The versions before CAM-L21C432B210, The versions before CAM-L21C464B170, The versions before CAM-L21C636B245, The versions before Berlin-L21C10B372, The versions before Berlin-L21C185B363, The versions before Berlin-L21C464B137, The versions before Berlin-L23C605B161, The versions before FRD-L09C10B387, The versions before FRD-L09C185B387, The versions before FRD-L09C432B398, The versions before FRD-L09C636B387, The versions before FRD-L19C10B387, The versions before FRD-L19C432B399, The versions before FRD-L19C636B387,

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.