Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2708

Опубликовано: 22 нояб. 2017
Источник: nvd
CVSS3: 4.6
CVSS2: 4.9
EPSS Низкий

Описание

The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:nice_firmware:*:*:*:*:*:*:*:*
Версия до nice-al00c00b0135 (исключая)
cpe:2.3:h:huawei:nice:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00192
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 4.6
github
больше 3 лет назад

The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

EPSS

Процентиль: 41%
0.00192
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-306