4.6

CVE-2016-8776

Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the Google account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P9 Firmware Version eva-al10c00
   Huawei ≫ P9 Version -
Huawei ≫ P9 Firmware Version eva-cl10c00
   Huawei ≫ P9 Version -
Huawei ≫ P9 Firmware Version eva-dl10c00
   Huawei ≫ P9 Version -
Huawei ≫ P9 Firmware Version eva-tl10c00
   Huawei ≫ P9 Version -
Huawei ≫ P9 Lite Firmware Version vns-l21c185
   Huawei ≫ P9 Lite Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.277
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 0.9 3.6
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161207-01-smartphone-en
Vendor Advisory
http://www.securityfocus.com/bid/94836
Third Party Advisory
VDB Entry