PT-2017-15495 · Huawei · Nice

Published

2017-11-22

·

Updated

2019-10-03

·

CVE-2017-2708

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Nice smartphones versions prior to Nice-AL00C00B0135
Description The issue concerns an authentication bypass in the 'Find Phone' function. This allows an unauthenticated attacker to potentially wipe and factory reset the phone by following specific steps, due to the lack of proper authentication in the 'Find Phone' function. As a result, an attacker could exploit this to bypass the intended security measures of the 'Find Phone' function, enabling them to use the phone normally without authorization.
Recommendations For versions prior to Nice-AL00C00B0135, as a temporary workaround, consider disabling the 'Find Phone' function until a patch is available. Restrict access to the 'Find Phone' feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2708

Affected Products

Nice