Vulnerability Description
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 6.0 | |
| Elephone | P9000 | - |
Related Weaknesses (CWE)
References
- https://www.reddit.com/r/netsec/comments/6kajkc/elephone_p9000_lock_screen_lockoPress/Media CoverageThird Party Advisory
- https://www.security.nl/posting/522081/Schermvergrendeling+Elephone+P9000+door+lThird Party Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-011/Third Party Advisory
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Elephone-P9000-Lock-Screen-LThird Party Advisory
- https://www.youtube.com/watch?v=dwyzonP2eZwPress/Media CoverageThird Party Advisory
- https://www.reddit.com/r/netsec/comments/6kajkc/elephone_p9000_lock_screen_lockoPress/Media CoverageThird Party Advisory
- https://www.security.nl/posting/522081/Schermvergrendeling+Elephone+P9000+door+lThird Party Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-011/Third Party Advisory
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Elephone-P9000-Lock-Screen-LThird Party Advisory
- https://www.youtube.com/watch?v=dwyzonP2eZwPress/Media CoverageThird Party Advisory
FAQ
What is CVE-2017-10709?
CVE-2017-10709 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.
How severe is CVE-2017-10709?
CVE-2017-10709 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10709?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Elephone P9000.