CVE-2017-17149 Vulnerability Details

  /     /     /  

CVE-2017-17149 Metadata Quick Info

CVE Published: 09/03/2018 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: huawei | Vendor: Huawei Technologies Co., Ltd. | Product: Huawei HiWallet App
Status : PUBLISHED

CVE-2017-17149 Description

Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user\'s Huawei ID during lock pattern change. An attacker with root privilege who gets a user\'s smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: arbitrary lock pattern change
Source: Huawei Technologies Co., Ltd.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).