CVE-2017-15351
Summary
| CVE | CVE-2017-15351 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-15 16:29:00 UTC |
| Updated | 2018-02-26 15:06:00 UTC |
| Description | The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' function. An attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Honor V9 Play | - | All | All | All |
| Hardware | Huawei | Honor V9 Play | - | All | All | All |
| Operating System | Huawei | Honor V9 Play Firmware | jimmy-al00ac00b135 | All | All | All |
| Operating System | Huawei | Honor V9 Play Firmware | jimmy-al00ac00b135 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Authentication Bypass Vulnerability in the 'Find Phone' Function of Some Huawei Smart Phones | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.