CVE-2017-8171: Medium severity Huawei P10 Plus Firmware vulnerability
Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to bypass the Google account verification. As a result, the FRP function is bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Huawei smart phone vulnerability?
The vulnerability ID for this Huawei smart phone vulnerability is CVE-2017-8171.
What is the severity of CVE-2017-8171?
The severity of CVE-2017-8171 is medium.
Which Huawei smart phone models are affected by CVE-2017-8171?
Huawei P10 Plus with software earlier than Vicky-AL00AC00B172D versions are affected by CVE-2017-8171.
How can an attacker exploit CVE-2017-8171?
An attacker can exploit CVE-2017-8171 by logging into Talkback mode during the factory reset protection (FRP) process and performing operations.
Is Huawei P10 Plus vulnerable to CVE-2017-8171?
No, Huawei P10 Plus is not vulnerable to CVE-2017-8171.