CVE Vulnerabilities

CVE-2017-17149

Published: Mar 09, 2018 | Modified: Oct 03, 2019
CVSS 3.x
3.9
LOW
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the users Huawei ID during lock pattern change. An attacker with root privilege who gets a users smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet.

Affected Software

Name Vendor Start Version End Version
Hiwallet Huawei * 8.0.4 (excluding)

References