CVE-2018-7956

Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulnerability in versions before 4.0.5 that attackers can conduct bruteforce to the VIP App Web Services to get user information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:huawei:vip_app:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:mate_20_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:nova_3i_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:nova_3i:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:nova_3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:nova_3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:13

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181129-01-huaweivip-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20181129-01-huaweivip-en - Vendor Advisory

Information

Published : 2018-12-04 18:29

Updated : 2024-11-21 04:13


NVD link : CVE-2018-7956

Mitre link : CVE-2018-7956

CVE.ORG link : CVE-2018-7956


JSON object : View

Products Affected

huawei

  • vip_app
  • nova_3
  • mate_20_firmware
  • mate_20
  • nova_3_firmware
  • nova_3i_firmware
  • nova_3i