CVE-2018-7988

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/11/2018
Last modified:
03/10/2019

Description

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:nova_2_plus_firmware:*:*:*:*:*:*:*:* 8.0.0.350\(c00\) (excluding)
cpe:2.3:h:huawei:nova_2_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_9_pro_firmware:*:*:*:*:*:*:*:* 8.0.0.363\(c00\) (excluding)
cpe:2.3:h:huawei:mate_9_pro:-:*:*:*:*:*:*:*