← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-7947

Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the device may exploit the vulnerability to bypass some specific function. Successful exploit may cause some malicious applications to be installed in the mobile phones.

No Active Exploit Signals
CVSS Base Score
3.9
LOW
EPSS Probability:0.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
Huawei Technologies Co., Ltd. Emily-AL00A Versions earlier before 8.1.0.153(C00) (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.236%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHuawei Technologies · Vendor · China
Reserved2018-03-09T00:00:00
Published2018-07-31T14:00:00
Patch Date2018-07-20
Last Updated2024-08-05T06:37:59

LINK COPIED TO CLIPBOARD