CVE-2017-8151
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
22/11/2017
Last modified:
20/04/2025
Description
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attacker can get a user's smart phone and install malicious apps in the mobile phone, allowing the attacker to reset the password and fingerprint of the phone without authentication.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:honor_5s_firmware:*:*:*:*:*:*:*:* | tag-tl00c01b173 (excluding) | |
| cpe:2.3:h:huawei:honor_5s:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



