PT-2017-18218 · Huawei · P10 Plus+6

Wen Guanxing

·

Published

2017-11-22

·

Updated

2020-08-24

·

CVE-2017-8214

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei Honor 8 versions earlier than FRD-AL00C00B391 Huawei Honor V8 versions earlier than FRD-DL00C00B391 Huawei Honor 9 versions earlier than KNT-AL10C00B391 Huawei Honor 9 versions earlier than KNT-AL20C00B391 Huawei Honor 9 versions earlier than KNT-UL10C00B391 Huawei Honor 9 versions earlier than KNT-TL10C00B391 Huawei Nova 2 versions earlier than Stanford-AL00C00B175 Huawei Nova 2 versions earlier than Stanford-AL10C00B175 Huawei Nova 2 versions earlier than Stanford-TL00C01B175 Huawei Nova 2 Plus versions earlier than Duke-AL20C00B191 Huawei Nova 2 Plus versions earlier than Duke-TL30C01B191 Huawei P9 versions earlier than Picasso-AL00C00B162 Huawei P9 versions earlier than Picasso-TL00C01B162 Huawei P10 Plus versions earlier than Barca-AL00C00B162 Huawei P10 Plus versions earlier than Barca-TL00C00B162 Huawei Toronto versions earlier than EVA-AL10C00B396SP03 Huawei Toronto versions earlier than EVA-CL00C92B396 Huawei Toronto versions earlier than EVA-DL00C17B396 Huawei Toronto versions earlier than EVA-TL00C01B396 Huawei Toronto versions earlier than Vicky-AL00AC00B172 Huawei Toronto versions earlier than Toronto-AL00AC00B191 Huawei Toronto versions earlier than Toronto-TL10C01B191
Description The issue is related to an unlock code verification bypassing vulnerability in certain Huawei smartphones. An attacker with root privilege of a mobile can exploit this vulnerability to bypass the unlock code verification and unlock the mobile phone bootloader.
Recommendations For Huawei Honor 8 versions earlier than FRD-AL00C00B391, update to a version later than FRD-AL00C00B391. For Huawei Honor V8 versions earlier than FRD-DL00C00B391, update to a version later than FRD-DL00C00B391. For Huawei Honor 9 versions earlier than KNT-AL10C00B391, update to a version later than KNT-AL10C00B391. For Huawei Honor 9 versions earlier than KNT-AL20C00B391, update to a version later than KNT-AL20C00B391. For Huawei Honor 9 versions earlier than KNT-UL10C00B391, update to a version later than KNT-UL10C00B391. For Huawei Honor 9 versions earlier than KNT-TL10C00B391, update to a version later than KNT-TL10C00B391. For Huawei Nova 2 versions earlier than Stanford-AL00C00B175, update to a version later than Stanford-AL00C00B175. For Huawei Nova 2 versions earlier than Stanford-AL10C00B175, update to a version later than Stanford-AL10C00B175. For Huawei Nova 2 versions earlier than Stanford-TL00C01B175, update to a version later than Stanford-TL00C01B175. For Huawei Nova 2 Plus versions earlier than Duke-AL20C00B191, update to a version later than Duke-AL20C00B191. For Huawei Nova 2 Plus versions earlier than Duke-TL30C01B191, update to a version later than Duke-TL30C01B191. For Huawei P9 versions earlier than Picasso-AL00C00B162, update to a version later than Picasso-AL00C00B162. For Huawei P9 versions earlier than Picasso-TL00C01B162, update to a version later than Picasso-TL00C01B162. For Huawei P10 Plus versions earlier than Barca-AL00C00B162, update to a version later than Barca-AL00C00B162. For Huawei P10 Plus versions earlier than Barca-TL00C00B162, update to a version later than Barca-TL00C00B162. For Huawei Toronto versions earlier than EVA-AL10C00B396SP03, update to a version later than EVA-AL10C00B396SP03. For Huawei Toronto versions earlier than EVA-CL00C92B396, update to a version later than EVA-CL00C92B396. For Huawei Toronto versions earlier than EVA-DL00C17B396, update to a version later than EVA-DL00C17B396. For Huawei Toronto versions earlier than EVA-TL00C01B396, update to a version later than EVA-TL00C01B396. For Huawei Toronto versions earlier than Vicky-AL00AC00B172, update to a version later than Vicky-AL00AC00B172. For Huawei Toronto versions earlier than Toronto-AL00AC00B191, update to a version later than Toronto-AL00AC00B191. For Huawei Toronto versions earlier than Toronto-TL10C01B191, update to a version later than Toronto-TL10C01B191.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8214

Affected Products

Honor 8
Honor 9
Nova 2
Nova 2 Plus
P10 Plus
P9
Toronto