Authentication Bypass Vulnerability in Huawei Honor 5S Smartphones
CVE-2017-8151

6.8MEDIUM

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The Huawei Honor 5S smartphones are susceptible to an authentication bypass vulnerability due to inadequate design in certain components. This flaw permits an attacker to exploit the device by installing malicious applications, granting them the ability to reset both the password and fingerprint settings of the phone without any authentication required. Proper security measures should be implemented to protect against unauthorized access.

Affected Version(s)

Honor 5S The versions before TAG-TL00C01B173

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.