CVE-2017-8173
Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162…
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than Victoria-AL00AC00B167 versions,earlier than Warsaw-AL00C00B200 versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by some secret code and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
- CVSS 3.0
- 4.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Affected
- huawei/maya-l02 firmware · huawei/vky-l09 firmware · huawei/vky-l29 firmware · huawei/vicky-al00a firmware · huawei/victoria-al00a firmware · huawei/warsaw-al00 firmware
- Source
- psirt@huawei.com
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170715-01-frpbypass-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170715-01-frpbypass-enIssue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.