Bluetooth Unlock Bypassing Vulnerability in Huawei Mobile Phones
CVE-2017-2728

6.4MEDIUM

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
15 November 2017

Summary

Huawei mobile phones, specifically the Honor 6X model and earlier versions, exhibit a vulnerability that allows an attacker to bypass the Bluetooth smart unlock feature. This security flaw stems from inadequate validation of Bluetooth devices. If the smart unlock function is enabled, an attacker can impersonate a trusted Bluetooth device, potentially gaining unauthorized access to the phone's screen and sensitive information. Users should take precautions to secure their devices and consider disabling the smart unlock feature until an update is applied.

Affected Version(s)

Honor 6X Berlin-L22C636B150 and earlier versions

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.