CVE-2017-8171

Description

Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to bypass the Google account verification. As a result, the FRP function is bypassed.

Risk Information

Base Score
4.6
MODERATE
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.027

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware vicky-al00ac00b172NCM
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware 9.1.0.255(c576e6r1p8t8)NCM
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware 9.1.0.252(c432e4r1p9t8)NCM
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware 9.1.0.252(c185e2r1p9t8)NCM
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware 9.1.0.201(c01e75r1p12t8)NCM
Vulnerabilities CVE-2017-8141 ,CVE-2017-8171 ,CVE-2017-8172 are affected in p10_plus_firmware 8.0.0.357(c00)NCM
Exposure of Resource to Wrong Sphere Vulnerability (CVE-2017-8171)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234