Description
Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8315 | Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID verification by special operation. Successful exploit of this vulnerability can allow an attacker to change the lock pattern of HiWallet. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T20:43:59.838Z
Reserved: 2017-12-04T00:00:00.000Z
Link: CVE-2017-17149
No data.
Status : Modified
Published: 2018-03-09T17:29:00.533
Modified: 2024-11-21T03:17:35.110
Link: CVE-2017-17149
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD