PT-2017-18160 · Huawei · Honor 5S

Zhang Qing

·

Published

2017-11-22

·

Updated

2017-12-11

·

CVE-2017-8151

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei Honor 5S versions prior to TAG-TL00C01B173
Description The issue is due to the improper design of some components, leading to an authentication bypass. This allows an attacker to install malicious apps on a user's smart phone, enabling them to reset the phone's password and fingerprint without authentication.
Recommendations For versions prior to TAG-TL00C01B173, update to version TAG-TL00C01B173 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8151

Affected Products

Honor 5S