CVE-2017-2721

UnknownEPSS 0.20%

Last modified

CVE-2017-2721 is a vulnerability of currently unknown severity. Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.

Metrics

EPSS Probability
0.20%

9.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiBerlin-L21 Firmwareberlin-l21c10b130
HuaweiBerlin-L21 Firmwareberlin-l21c185b133
HuaweiBerlin-L21hn Firmwareberlin-l21hnc10b131
HuaweiBerlin-L21hn Firmwareberlin-l21hnc185b140
HuaweiBerlin-L21hn Firmwareberlin-l21hnc432b151
HuaweiBerlin-L22 Firmwareberlin-l22c636b160
HuaweiBerlin-L22hn Firmwareberlin-l22hnc636b130
HuaweiBerlin-L22hn Firmwareberlin-l22hnc675b150custc675d001
HuaweiBerlin-L23 Firmwareberlin-l23c605b131
HuaweiBerlin-L24hn Firmwareberlin-l24hnc567b110
HuaweiFrd-L02 Firmwarefrd-l02c432b120
HuaweiFrd-L02 Firmwarefrd-l02c635b130
HuaweiFrd-L02 Firmwarefrd-l02c675b170custc675d001
HuaweiFrd-L04 Firmwarefrd-l04c567b162
HuaweiFrd-L04 Firmwarefrd-l04c605b131
HuaweiFrd-L09 Firmwarefrd-l09c10b130
HuaweiFrd-L09 Firmwarefrd-l09c185b130
HuaweiFrd-L09 Firmwarefrd-l09c432b131
HuaweiFrd-L09 Firmwarefrd-l09c636b130
HuaweiFrd-L14 Firmwarefrd-l14c567b162
HuaweiFrd-L19 Firmwarefrd-l19c10b130
HuaweiFrd-L19 Firmwarefrd-l19c432b131
HuaweiFrd-L19 Firmwarefrd-l19c636b130

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-2721?
Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.
How severe is CVE-2017-2721?
Severity scoring for CVE-2017-2721 is pending analysis. The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2017-2721?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-2721?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST