4.6
CVE-2016-8776
- EPSS 0.03%
- Veröffentlicht 02.04.2017 20:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@huawei.com
- CVE-Watchlists
- Unerledigt
Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the Google account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P9 Firmware Versioneva-al10c00
Huawei ≫ P9 Firmware Versioneva-cl10c00
Huawei ≫ P9 Firmware Versioneva-dl10c00
Huawei ≫ P9 Firmware Versioneva-tl10c00
Huawei ≫ P9 Lite Firmware Versionvns-l21c185
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 0.9 | 3.6 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.