« Back to list

CVE-2017-8161

Status: ModifiedMedium (4.6)—

EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Swype and can perform some operations to update the Google account. As a result, the FRP function is bypassed.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-8161",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:C/A:N",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.6,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei Technologies Co., Ltd.",
          "product": "EVA-L09",
          "versions": [
            {
              "status": "affected",
              "version": "Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-22T19:29:03.740",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171013-01-frpbypass-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171013-01-frpbypass-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-668"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Swype and can perform some operations to update the Google account. As a result, the FRP function is bypassed."
    },
    {
      "lang": "es",
      "value": "Los smartphones EVA-L09 con software anterior a las versiones EVA-L09C25B150CUSTC25D003, EVA-L09C440B140, EVA-L09C464B361 y EVA-L09C675B320CUSTC675D004 tienen una vulnerabilidad de omisión de Factory Reset Protection (FRP). Cuando se reconfigura el teléfono móvil utilizando la función Factory Reset Protection (FRP), un atacante puede iniciar sesión en Swype y realizar determinadas operaciones para actualizar la cuenta de Google. El resultado es que la función FRP se omite."
    }
  ],
  "lastModified": "2026-06-17T01:25:53.340",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEA0A8C6-485E-49D4-A924-2671F594EB7A",
              "versionEndExcluding": "eva-l09c25b150custc25d003"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:eva-l09:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A321BCC8-2C89-4D53-914D-3CDC1247E0FD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A6644E1-0919-4B43-B2CE-9C05A42726B3",
              "versionEndExcluding": "eva-l09c440b140"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:eva-l09:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A321BCC8-2C89-4D53-914D-3CDC1247E0FD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BB54335-DBFD-4062-BDA3-D595BA872DA5",
              "versionEndExcluding": "eva-l09c464b361"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:eva-l09:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A321BCC8-2C89-4D53-914D-3CDC1247E0FD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D09445B1-BEBB-47B2-8270-613E9DE14897",
              "versionEndExcluding": "l09c675b320custc675d004"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:eva-l09:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A321BCC8-2C89-4D53-914D-3CDC1247E0FD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}