First published: Wed Nov 22 2017(Updated: )
Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to bypass the Google account verification. As a result, the FRP function is bypassed.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Plus Firmware | <vicky-al00ac00b172d | |
Huawei P10 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei smart phone vulnerability is CVE-2017-8171.
The severity of CVE-2017-8171 is medium.
Huawei P10 Plus with software earlier than Vicky-AL00AC00B172D versions are affected by CVE-2017-8171.
An attacker can exploit CVE-2017-8171 by logging into Talkback mode during the factory reset protection (FRP) process and performing operations.
No, Huawei P10 Plus is not vulnerable to CVE-2017-8171.