CVE Vulnerabilities

CVE-2017-17326

Published: Mar 09, 2018 | Modified: Oct 03, 2019
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to bypass the activation lock and activate the smartphone by a new account after a series of operation.

Affected Software

Name Vendor Start Version End Version
Mate_9_pro_fimware Huawei lon-al00bc00b139d (including) lon-al00bc00b139d (including)
Mate_9_pro_fimware Huawei lon-al00bc00b229 (including) lon-al00bc00b229 (including)

References