First published: Wed Nov 22 2017(Updated: )
EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Swype and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Eva-L09 Firmware | <eva-l09c25b150custc25d003 | |
Huawei Eva-L09 Firmware | ||
Huawei Eva-L09 Firmware | <eva-l09c440b140 | |
Huawei Eva-L09 Firmware | <eva-l09c464b361 | |
Huawei Eva-L09 Firmware | <l09c675b320custc675d004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8161 is considered a high severity vulnerability due to the potential for unauthorized access to the device.
To fix CVE-2017-8161, update your Huawei EVA-L09 device to the latest firmware version EVA-L09C25B150CUSTC25D003 or a later version.
CVE-2017-8161 affects Huawei EVA-L09 smartphones with software versions earlier than EVA-L09C25B150CUSTC25D003, EVA-L09C440B140, EVA-L09C464B361, and EVA-L09C675B320CUSTC675D004.
The Factory Reset Protection bypass vulnerability in CVE-2017-8161 allows an attacker to reset the device without the original owner's Google account credentials.
There is no effective workaround for CVE-2017-8161 other than updating to a secure version of the firmware.