4 results (0.007 seconds)

CVSS: 4.6EPSS: 0%CPEs: 122EXPL: 0

08 Jun 2020 — Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en. Algunos teléfonos inteligentes Huawei presentan una vulnerabilidad de seguridad que omite la Factory Reset Protec... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en •

CVSS: 6.5EPSS: 0%CPEs: 38EXPL: 0

21 May 2020 — There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly. Affected product versions include: Anne-AL00 Versions earlier than 9.1.0.331(C675E9R1P3T8); Berkeley-L09 Versions earlier than 10.0.1.1(C675R1); CD16-10 Versions earlier than 10.0.2.8; CD17-10 Versions earlier than 10.0.2.8; CD17-16 Versions earlier than 10.0.2.8; CD18-10 Versions earlier than 10.... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200520-01-leakage-en •

CVSS: 10.0EPSS: 51%CPEs: 159EXPL: 29

04 Oct 2019 — A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095 Un uso de la memoria previamente liberada en el archivo binder.c, permite una elevación de privilegios desde una aplicación en el kernel de Linux. No es re... • https://packetstorm.news/files/id/156495 • CWE-416: Use After Free •

CVSS: 2.4EPSS: 0%CPEs: 2EXPL: 0

17 Oct 2018 — Anne-AL00 Huawei phones with versions earlier than 8.0.0.151(C00) have an information leak vulnerability. Due to improper permission settings for specific commands, attackers who can connect to a mobile phone via the USB interface may exploit this vulnerability to obtain specific device information of the mobile phone. Los smartphones Huawei Anne-AL00 con versiones anteriores a la 8.0.0.151(C00) tienen una vulnerabilidad de filtrado de información. Debido a la configuración de permisos incorrecta para coman... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181017-01-smartphone-en • CWE-732: Incorrect Permission Assignment for Critical Resource •