MEDIUM · 4.6

CVE-2017-2721

Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CU...

Vulnerability Description

Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.

CVSS Score

4.6

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
HuaweiBerlin-L21 Firmwareberlin-l21c10b130
HuaweiBerlin-L21-
HuaweiBerlin-L21Hn Firmwareberlin-l21hnc10b131
HuaweiBerlin-L21Hn-
HuaweiBerlin-L22 Firmwareberlin-l22c636b160
HuaweiBerlin-L22-
HuaweiBerlin-L22Hn Firmwareberlin-l22hnc636b130
HuaweiBerlin-L22Hn-
HuaweiBerlin-L23 Firmwareberlin-l23c605b131
HuaweiBerlin-L23-
HuaweiBerlin-L24Hn Firmwareberlin-l24hnc567b110
HuaweiBerlin-L24Hn-
HuaweiFrd-L02 Firmwarefrd-l02c432b120
HuaweiFrd-L02-
HuaweiFrd-L04 Firmwarefrd-l04c567b162
HuaweiFrd-L04-
HuaweiFrd-L09 Firmwarefrd-l09c10b130
HuaweiFrd-L09-
HuaweiFrd-L14 Firmwarefrd-l14c567b162
HuaweiFrd-L14-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-2721?

CVE-2017-2721 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CU...

How severe is CVE-2017-2721?

CVE-2017-2721 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-2721?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Berlin-L21 Firmware, Huawei Berlin-L21, Huawei Berlin-L21Hn Firmware, Huawei Berlin-L21Hn, Huawei Berlin-L22 Firmware.