Vulnerability Description
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attacker can get a user's smart phone and install malicious apps in the mobile phone, allowing the attacker to reset the password and fingerprint of the phone without authentication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 5S Firmware | < tag-tl00c01b173 |
| Huawei | Honor 5S | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-03-smartphVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-03-smartphVendor Advisory
FAQ
What is CVE-2017-8151?
CVE-2017-8151 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attacker can get a user's s...
How severe is CVE-2017-8151?
CVE-2017-8151 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8151?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Honor 5S Firmware, Huawei Honor 5S.