CVE-2017-8151

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/11/2017
Last modified:
20/04/2025

Description

Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attacker can get a user's smart phone and install malicious apps in the mobile phone, allowing the attacker to reset the password and fingerprint of the phone without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:honor_5s_firmware:*:*:*:*:*:*:*:* tag-tl00c01b173 (excluding)
cpe:2.3:h:huawei:honor_5s:-:*:*:*:*:*:*:*