Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-8171

Опубликовано: 22 нояб. 2017
Источник: nvd
CVSS3: 4.6
CVSS2: 4.9
EPSS Низкий

Описание

Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to bypass the Google account verification. As a result, the FRP function is bypassed.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:*
Версия до vicky-al00ac00b172d (исключая)
cpe:2.3:h:huawei:p10_plus:-:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00027
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.6
github
больше 3 лет назад

Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to bypass the Google account verification. As a result, the FRP function is bypassed.

EPSS

Процентиль: 7%
0.00027
Низкий

4.6 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-668