First published: Wed Nov 22 2017(Updated: )
Huawei P9 smartphones with software versions earlier before EVA-AL10C00B365, versions earlier before EVA-AL00C00B365, versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a phone activation bypass vulnerability. Successful exploit could allow an unauthenticated attacker to bypass phone activation to settings page of the phone.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P9 Firmware | <eva-al00c00b365 | |
Huawei P9 | ||
Huawei P9 Firmware | <eva-al10c00b365 | |
Huawei P9 Firmware | <eva-cl00c92b365 | |
Huawei P9 Firmware | <eva-dl00c17b365 | |
Huawei P9 Firmware | <eva-tl00c01b365 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei P9 vulnerability is CVE-2017-2705.
The severity of CVE-2017-2705 is low with a CVSS score of 2.4.
The affected software for CVE-2017-2705 is Huawei P9 smartphones with software versions earlier than EVA-AL10C00B365, versions earlier than EVA-AL00C00B365, versions earlier than EVA-CL00C92B365, versions earlier than EVA-DL00C17B365, versions earlier than EVA-TL00C01B365.
To fix CVE-2017-2705, update the software of Huawei P9 smartphones to versions EVA-AL10C00B365, EVA-AL00C00B365, EVA-CL00C92B365, EVA-DL00C17B365, EVA-TL00C01B365 or later.
No, Huawei P9 smartphones without the affected software versions are not vulnerable to CVE-2017-2705.