PT-2017-18160 · Huawei · Honor 5S
Zhang Qing
·
Publicado
2017-11-22
·
Atualizado
2017-12-11
·
CVE-2017-8151
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei Honor 5S versions prior to TAG-TL00C01B173
Description
The issue is due to the improper design of some components, leading to an authentication bypass. This allows an attacker to install malicious apps on a user's smart phone, enabling them to reset the phone's password and fingerprint without authentication.
Recommendations
For versions prior to TAG-TL00C01B173, update to version TAG-TL00C01B173 or later to resolve the issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Honor 5S