CVE-2017-2728: Medium severity Huawei Honor 6x Firmware vulnerability
Some Huawei mobile phones Honor 6X Berlin-L22C636B150 and earlier versions have a Bluetooth unlock bypassing vulnerability. If a user has enabled the smart unlock function, an attacker can impersonate the user's Bluetooth device to unlock the user's mobile phone screen.uawei mobile phones have a Bluetooth unlock bypassing vulnerability due to the lack of validation on Bluetooth devices. If a user has enabled the smart unlock function, an attacker can impersonate the user's Bluetooth device to unlock the user's mobile phone screen.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-2728.
What is the affected software?
The affected software is Huawei Honor 6X with Berlin-L22C636B150 firmware and earlier versions.
What is the severity of CVE-2017-2728?
The severity of CVE-2017-2728 is medium with a CVSSv3 score of 6.4.
How does the vulnerability work?
If a user has enabled the smart unlock function, an attacker can impersonate the user's Bluetooth device to unlock the user's mobile phone screen.
Is there a fix for CVE-2017-2728?
Yes, Huawei has released a security advisory detailing the issue and providing recommended updates or patches.