Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: huawei
Published: 2018-03-09T17:00:00
Updated: 2024-08-05T20:43:59.838Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2017-17149
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2018-03-09T17:29:00.533
Modified: 2019-10-03T00:03:26.223
Link: CVE-2017-17149
Redhat
No data.