CVE-2017-17326

UnknownEPSS 0.24%

Last modified

CVE-2017-17326 is a vulnerability of currently unknown severity. Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to bypass the activation lock and activate the smartphone by a new account after a series of operation.

Metrics

EPSS Probability
0.24%

14.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HuaweiMate 9 Pro Fimwarelon-al00bc00b139d
HuaweiMate 9 Pro Fimwarelon-al00bc00b229

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-17326?
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to bypass the activation lock and activate the smartphone by a new account after a series of operation.
How severe is CVE-2017-17326?
Severity scoring for CVE-2017-17326 is pending analysis. The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2017-17326?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-17326?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST