ZeroHour

CVE-2017-17149

CVSS 3.0
3.9 low
EPSS
<1%p13
Published
()
Modified
Description

Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet.

Vendors
huawei
Products
hiwallet
Vector
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.