PT-2017-18179 · Huawei · Victoria-Al00A+5

Pedro Simoes

·

Published

2017-11-22

·

Updated

2019-10-03

·

CVE-2017-8173

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Maya-L02 versions earlier than C636B126 VKY-L09 versions earlier than C10B151 VTR-L29 versions earlier than C10B151 Vicky-AL00A versions earlier than C00B162 Victoria-AL00A versions earlier than C00B167 Warsaw-AL00 versions earlier than C00B200
Description The issue allows an attacker to bypass the Factory Reset Protection (FRP) security feature by using a secret code to login to the configuration flow during a factory reset. This enables the attacker to perform operations that update the Google account, effectively bypassing the FRP function.
Recommendations For Maya-L02 versions earlier than C636B126, update to version C636B126 or later to resolve the issue. For VKY-L09 versions earlier than C10B151, update to version C10B151 or later to resolve the issue. For VTR-L29 versions earlier than C10B151, update to version C10B151 or later to resolve the issue. For Vicky-AL00A versions earlier than C00B162, update to version C00B162 or later to resolve the issue. For Victoria-AL00A versions earlier than C00B167, update to version C00B167 or later to resolve the issue. For Warsaw-AL00 versions earlier than C00B200, update to version C00B200 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-8173

Affected Products

Maya-L02
Vky-L09
Vtr-L29
Vicky-Al00A
Victoria-Al00A
Warsaw-Al00