CVE-2017-2710

BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than BTV-W09C331B002CUSTC331D001 versions, earlier than CRR-L09C432B390 versions, earlier than CRR-L09C605B355CUSTC605D003 versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can perform some operations to update the Google account. As a result, the FRP function is bypassed.
References
Link Resource
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170524-01-frp-en Issue Tracking Vendor Advisory
http://www.securityfocus.com/bid/98712 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:btv-w09c229b002custc229d005:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:btv-w09c233b029:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:beethoven-w09a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:beethoven-w09a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:huawei:crr-l09_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:crr-l09:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:huawei:crr-l09_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:crr-l09:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-22 19:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-2710

Mitre link : CVE-2017-2710

CVE.ORG link : CVE-2017-2710


JSON object : View

Products Affected

huawei

  • beethoven-w09a
  • crr-l09
  • beethoven-w09a_firmware
  • crr-l09_firmware