Vulnerability Description
Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerability due to the improper design of a component. An attacker who get a user's smart phone can execute specific operation, and delete the fingerprint of the phone without authentication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor V9 Play Firmware | < jimmy-al00ac00b135 |
| Huawei | Honor V9 Play | - |
References
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171213-03-smVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171213-03-smVendor Advisory
FAQ
What is CVE-2017-17145?
CVE-2017-17145 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerability due to the improper design of a component. An attacker who get a user's smart ...
How severe is CVE-2017-17145?
CVE-2017-17145 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17145?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Honor V9 Play Firmware, Huawei Honor V9 Play.