ID

VAR-201804-1331


CVE

CVE-2018-7931


TITLE

Huawei AppGallery Vulnerabilities related to security functions

Trust: 0.8

sources: JVNDB: JVNDB-2018-004567

DESCRIPTION

Huawei AppGallery versions before 8.0.4.301 has a whitelist mechanism bypass vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism. Huawei AppGallery Contains vulnerabilities related to security features.Information may be tampered with. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Huawei App Market. The issue lies in the lack of verification that content was loaded over a secure channel. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the application. Huawei AppGallery is a software integrated in Huawei mobile phones for downloading third-party applications from Huawei of China

Trust: 2.34

sources: NVD: CVE-2018-7931 // JVNDB: JVNDB-2018-004567 // ZDI: ZDI-18-879 // VULHUB: VHN-137963

AFFECTED PRODUCTS

vendor:huaweimodel:appgalleryscope:ltversion:8.0.4.301

Trust: 1.8

vendor:huaweimodel:app marketscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-18-879 // JVNDB: JVNDB-2018-004567 // NVD: CVE-2018-7931

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7931
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-7931
value: MEDIUM

Trust: 0.8

ZDI: CVE-2018-7931
value: MEDIUM

Trust: 0.7

CNNVD: CNNVD-201804-1389
value: MEDIUM

Trust: 0.6

VULHUB: VHN-137963
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-7931
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ZDI: CVE-2018-7931
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

VULHUB: VHN-137963
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7931
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: ZDI: ZDI-18-879 // VULHUB: VHN-137963 // JVNDB: JVNDB-2018-004567 // CNNVD: CNNVD-201804-1389 // NVD: CVE-2018-7931

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-254

Trust: 0.9

sources: VULHUB: VHN-137963 // JVNDB: JVNDB-2018-004567 // NVD: CVE-2018-7931

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201804-1389

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201804-1389

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-004567

PATCH

title:huawei-sa-20180423-01-appurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180423-01-app-en

Trust: 1.5

title:Huawei AppGallery Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79671

Trust: 0.6

sources: ZDI: ZDI-18-879 // JVNDB: JVNDB-2018-004567 // CNNVD: CNNVD-201804-1389

EXTERNAL IDS

db:NVDid:CVE-2018-7931

Trust: 3.2

db:JVNDBid:JVNDB-2018-004567

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-5347

Trust: 0.7

db:ZDIid:ZDI-18-879

Trust: 0.7

db:CNNVDid:CNNVD-201804-1389

Trust: 0.7

db:VULHUBid:VHN-137963

Trust: 0.1

sources: ZDI: ZDI-18-879 // VULHUB: VHN-137963 // JVNDB: JVNDB-2018-004567 // CNNVD: CNNVD-201804-1389 // NVD: CVE-2018-7931

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180423-01-app-en

Trust: 2.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7931

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7931

Trust: 0.8

sources: ZDI: ZDI-18-879 // VULHUB: VHN-137963 // JVNDB: JVNDB-2018-004567 // CNNVD: CNNVD-201804-1389 // NVD: CVE-2018-7931

CREDITS

MWR Labs - Alex Plaskett James Loureiro Robert Miller and Georgi Geshev

Trust: 0.7

sources: ZDI: ZDI-18-879

SOURCES

db:ZDIid:ZDI-18-879
db:VULHUBid:VHN-137963
db:JVNDBid:JVNDB-2018-004567
db:CNNVDid:CNNVD-201804-1389
db:NVDid:CVE-2018-7931

LAST UPDATE DATE

2024-11-23T22:45:23.563000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-18-879date:2018-08-02T00:00:00
db:VULHUBid:VHN-137963date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-004567date:2018-06-25T00:00:00
db:CNNVDid:CNNVD-201804-1389date:2019-10-23T00:00:00
db:NVDid:CVE-2018-7931date:2024-11-21T04:12:58.677

SOURCES RELEASE DATE

db:ZDIid:ZDI-18-879date:2018-08-02T00:00:00
db:VULHUBid:VHN-137963date:2018-04-24T00:00:00
db:JVNDBid:JVNDB-2018-004567date:2018-06-25T00:00:00
db:CNNVDid:CNNVD-201804-1389date:2018-04-25T00:00:00
db:NVDid:CVE-2018-7931date:2018-04-24T15:29:00.947