PT-2017-18160 · Huawei · Honor 5S
Zhang Qing
·
Published
2017-11-22
·
Updated
2017-12-11
·
CVE-2017-8151
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei Honor 5S versions prior to TAG-TL00C01B173
Description
The issue is due to the improper design of some components, leading to an authentication bypass. This allows an attacker to install malicious apps on a user's smart phone, enabling them to reset the phone's password and fingerprint without authentication.
Recommendations
For versions prior to TAG-TL00C01B173, update to version TAG-TL00C01B173 or later to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Honor 5S