PT-2017-9804 · Huawei · Huawei P9+1
Aung Khant Zaw
·
Published
2017-04-02
·
Updated
2017-04-10
·
CVE-2016-8776
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei P9 phones versions EVA-AL10C00, EVA-CL10C00, EVA-DL10C00, EVA-TL10C00
Huawei P9 Lite phones version VNS-L21C185
Description
The issue allows attackers to bypass the factory reset protection (FRP) and enter some functional modules without authorization, enabling them to perform operations such as updating the Google account.
Recommendations
For Huawei P9 phones versions EVA-AL10C00, EVA-CL10C00, EVA-DL10C00, EVA-TL10C00, update the software to a version that fixes the FRP bypass issue.
For Huawei P9 Lite phones version VNS-L21C185, update the software to a version that fixes the FRP bypass issue.
As a temporary workaround, consider restricting access to functional modules that can be entered without authorization until a patch is available.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei P9
Huawei P9 Lite