Factory Reset Protection Bypass in Huawei Smartphones
CVE-2017-8171

4.6MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
22 November 2017

Summary

Huawei smartphones running software versions earlier than Vicky-AL00AC00B172 are vulnerable to a Factory Reset Protection (FRP) bypass. This security flaw allows an attacker to exploit the Talkback mode to circumvent Google account verification during the device reconfiguration process. As a consequence, malicious users can regain access to a device after a factory reset, undermining the device's security measures. Users of affected Huawei models are encouraged to update their software to the latest versions to mitigate this vulnerability.

Affected Version(s)

Vicky-AL00A Earlier than Vicky-AL00AC00B172D versions

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.