CVE-2017-2721
Last modified
CVE-2017-2721 is a vulnerability of currently unknown severity. Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Berlin-L21 Firmware | berlin-l21c10b130 |
| Huawei | Berlin-L21 Firmware | berlin-l21c185b133 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc10b131 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc185b140 |
| Huawei | Berlin-L21hn Firmware | berlin-l21hnc432b151 |
| Huawei | Berlin-L22 Firmware | berlin-l22c636b160 |
| Huawei | Berlin-L22hn Firmware | berlin-l22hnc636b130 |
| Huawei | Berlin-L22hn Firmware | berlin-l22hnc675b150custc675d001 |
| Huawei | Berlin-L23 Firmware | berlin-l23c605b131 |
| Huawei | Berlin-L24hn Firmware | berlin-l24hnc567b110 |
| Huawei | Frd-L02 Firmware | frd-l02c432b120 |
| Huawei | Frd-L02 Firmware | frd-l02c635b130 |
| Huawei | Frd-L02 Firmware | frd-l02c675b170custc675d001 |
| Huawei | Frd-L04 Firmware | frd-l04c567b162 |
| Huawei | Frd-L04 Firmware | frd-l04c605b131 |
| Huawei | Frd-L09 Firmware | frd-l09c10b130 |
| Huawei | Frd-L09 Firmware | frd-l09c185b130 |
| Huawei | Frd-L09 Firmware | frd-l09c432b131 |
| Huawei | Frd-L09 Firmware | frd-l09c636b130 |
| Huawei | Frd-L14 Firmware | frd-l14c567b162 |
| Huawei | Frd-L19 Firmware | frd-l19c10b130 |
| Huawei | Frd-L19 Firmware | frd-l19c432b131 |
| Huawei | Frd-L19 Firmware | frd-l19c636b130 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-frpbypass-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-frpbypass-enIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2721?
How severe is CVE-2017-2721?
How do I fix CVE-2017-2721?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2715The Files APP 7.1.1.309 and earlier versions in some Huawei …
- CVE-2017-2716The camerafs driver in Mate 9 Versions earlier than MHA-AL00…
- CVE-2017-2717honor 8 Pro with software Duke-L09C10B120 and earlier versio…
- CVE-2017-2718FusionSphere OpenStack with software V100R006C00 and V100R00…8.8
- CVE-2017-2719FusionSphere OpenStack with software V100R006C00 and V100R00…
- CVE-2017-2720FusionSphere OpenStack V100R006C00 has an information exposu…
- CVE-2017-2722DP300 V500R002C00,TE60 with software V100R001C01, V100R001C1…
- CVE-2017-2723The Files APP 7.1.1.308 and earlier versions in some Huawei …
- CVE-2017-2724Bastet in P10 Plus and P10 smart phones with software earlie…
- CVE-2017-2725Bastet in P10 Plus and P10 smart phones with software earlie…
- CVE-2017-2726Bastet in P10 Plus and P10 smart phones with software earlie…
- CVE-2017-2727Huawei P9 smart phones with software versions earlier before…
Are you affected by CVE-2017-2721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
