CVE-2018-7956
 
Severity Score
5.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulnerability in versions before 4.0.5 that attackers can conduct bruteforce to the VIP App Web Services to get user information.
Huawei VIP App es una aplicación móvil para los clientes de Malasia que adquirieron los modelos P20 Series, Nova 3/3i y Mate 20. Hay una vulnerabilidad en las versiones anteriores a la 4.0.5 que permite que los atacantes lleven a cabo ataques de fuerza bruta contra VIP App Web Services para obtener información de usuario.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-03-09 CVE Reserved
- 2018-12-04 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181129-01-huaweivip-en | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 20 Firmware Search vendor "Huawei" for product "Mate 20 Firmware" | - | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 Search vendor "Huawei" for product "Mate 20" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Nova 3i Firmware Search vendor "Huawei" for product "Nova 3i Firmware" | - | - |
Affected
| in | Huawei Search vendor "Huawei" | Nova 3i Search vendor "Huawei" for product "Nova 3i" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Nova 3 Firmware Search vendor "Huawei" for product "Nova 3 Firmware" | - | - |
Affected
| in | Huawei Search vendor "Huawei" | Nova 3 Search vendor "Huawei" for product "Nova 3" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Vip App Search vendor "Huawei" for product "Vip App" | < 4.0.5 Search vendor "Huawei" for product "Vip App" and version " < 4.0.5" | - |
Affected
|