PT-2017-15497 · Huawei · Btv-W09C100B006Custc100D002+8

Alessandro De Bartolo

·

Published

2017-11-22

·

Updated

2019-10-03

·

CVE-2017-2710

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BTV-W09C229B002CUSTC229D005 BTV-W09C233B029 BTV-W09C100B006CUSTC100D002 versions earlier than BTV-W09C100B006CUSTC100D002 BTV-W09C128B003CUSTC128D002 versions earlier than BTV-W09C128B003CUSTC128D002 BTV-W09C199B002CUSTC199D002 versions earlier than BTV-W09C199B002CUSTC199D002 BTV-W09C209B005CUSTC209D001 versions earlier than BTV-W09C209B005CUSTC209D001 BTV-W09C331B002CUSTC331D001 versions earlier than BTV-W09C331B002CUSTC331D001 CRR-L09C432B390 versions earlier than CRR-L09C432B390 CRR-L09C605B355CUSTC605D003 versions earlier than CRR-L09C605B355CUSTC605D003
Description The issue concerns a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can perform some operations to update the Google account, resulting in the FRP function being bypassed.
Recommendations For BTV-W09C229B002CUSTC229D005, update to a version later than BTV-W09C229B002CUSTC229D005. For BTV-W09C233B029, update to a version later than BTV-W09C233B029. For versions earlier than BTV-W09C100B006CUSTC100D002, update to BTV-W09C100B006CUSTC100D002 or later. For versions earlier than BTV-W09C128B003CUSTC128D002, update to BTV-W09C128B003CUSTC128D002 or later. For versions earlier than BTV-W09C199B002CUSTC199D002, update to BTV-W09C199B002CUSTC199D002 or later. For versions earlier than BTV-W09C209B005CUSTC209D001, update to BTV-W09C209B005CUSTC209D001 or later. For versions earlier than BTV-W09C331B002CUSTC331D001, update to BTV-W09C331B002CUSTC331D001 or later. For versions earlier than CRR-L09C432B390, update to CRR-L09C432B390 or later. For versions earlier than CRR-L09C605B355CUSTC605D003, update to CRR-L09C605B355CUSTC605D003 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-2710

Affected Products

Btv-W09C100B006Custc100D002
Btv-W09C128B003Custc128D002
Btv-W09C199B002Custc199D002
Btv-W09C209B005Custc209D001
Btv-W09C229B002Custc229D005
Btv-W09C233B029
Btv-W09C331B002Custc331D001
Crr-L09C432B390
Crr-L09C605B355Custc605D003