CVE-2017-2721
Last modified
CVE-2017-2721 is a vulnerability of currently unknown severity. Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Berlin-L21 Firmware | berlin-l21c10b130 |
| Huawei | Berlin-L21 Firmware | berlin-l21c185b133 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc10b131 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc185b140 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc432b151 |
| Huawei | Berlin-L22 Firmware | berlin-l22c636b160 |
| Huawei | Berlin-L22hn Firmware | berlin-l22hnc636b130 |
| Huawei | Berlin-L22hn Firmware | berlin-l22hnc675b150custc675d001 |
| Huawei | Berlin-L23 Firmware | berlin-l23c605b131 |
| Huawei | Berlin-L24hn Firmware | berlin-l24hnc567b110 |
| Huawei | Frd-L02 Firmware | frd-l02c432b120 |
| Huawei | Frd-L02 Firmware | frd-l02c635b130 |
| Huawei | Frd-L02 Firmware | frd-l02c675b170custc675d001 |
| Huawei | Frd-L04 Firmware | frd-l04c567b162 |
| Huawei | Frd-L04 Firmware | frd-l04c605b131 |
| Huawei | Frd-L09 Firmware | frd-l09c10b130 |
| Huawei | Frd-L09 Firmware | frd-l09c185b130 |
| Huawei | Frd-L09 Firmware | frd-l09c432b131 |
| Huawei | Frd-L09 Firmware | frd-l09c636b130 |
| Huawei | Frd-L14 Firmware | frd-l14c567b162 |
| Huawei | Frd-L19 Firmware | frd-l19c10b130 |
| Huawei | Frd-L19 Firmware | frd-l19c432b131 |
| Huawei | Frd-L19 Firmware | frd-l19c636b130 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-frpbypass-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-frpbypass-enIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2721?
How severe is CVE-2017-2721?
How do I fix CVE-2017-2721?
Are you affected by CVE-2017-2721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
