Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-2691


Huawei P9 versions earlier before EVA-AL10C00B373, versions earlier before EVA-CL00C92B373, versions earlier before EVA-DL00C17B373, versions earlier before EVA-TL00C01B373 have a lock-screen bypass vulnerability. An unauthenticated attacker could force the phone to the fastboot mode and delete the user's password file during the reboot process, then login the phone without screen lock password after reboot.


Published

2017-11-22T19:29:00.287

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei p9_firmware < eva-tl00c01b373 Yes
Hardware huawei p9 - No
Operating System huawei p9_firmware < eva-dl00c17b373 Yes
Hardware huawei p9 - No
Operating System huawei p9_firmware < eva-cl00c92b373 Yes
Hardware huawei p9 - No
Operating System huawei p9_firmware < eva-al10c00b373 Yes
Hardware huawei p9 - No

References