Authentication Bypass Vulnerability in Huawei Mate 9 Pro Smartphone
CVE-2017-17279

5.5MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
9 March 2018

Summary

The soundtrigger module in Huawei Mate 9 Pro smartphones before version LON-AL00B 8.0.0.343(C00) presents an authentication bypass vulnerability. This flaw allows attackers to exploit the system by deceiving users into installing malicious applications. Once executed, the compromised application can circumvent authentication mechanisms, granting attackers control over the device. They can send unauthorized text messages and initiate calls within audio range, posing significant security risks to users.

Affected Version(s)

Mate 9 Pro The versions before LON-AL00B 8.0.0.343(C00)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.