Vulnerability Intelligence Report
CVE-2018-7947
Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the device may exploit the vulnerability to bypass some specific function. Successful exploit may cause some malicious applications to be installed in the mobile phones.
No Active Exploit Signals
CVSS Base Score
3.9
LOW
EPSS Probability:0.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Huawei Technologies Co., Ltd. | Emily-AL00A | Versions earlier before 8.1.0.153(C00) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.236%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Huawei Technologies · Vendor · China |
| Reserved | 2018-03-09T00:00:00 |
| Published | 2018-07-31T14:00:00 |
| Patch Date | 2018-07-20 |
| Last Updated | 2024-08-05T06:37:59 |
Community Chatter & Buzz