PT-2017-18160 · Huawei · Honor 5S

Zhang Qing

·

Publicado

2017-11-22

·

Atualizado

2017-12-11

·

CVE-2017-8151

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei Honor 5S versions prior to TAG-TL00C01B173
Description The issue is due to the improper design of some components, leading to an authentication bypass. This allows an attacker to install malicious apps on a user's smart phone, enabling them to reset the phone's password and fingerprint without authentication.
Recommendations For versions prior to TAG-TL00C01B173, update to version TAG-TL00C01B173 or later to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8151

Produtos afetados

Honor 5S