CVE-2016-8776

CWE-2854 documents4 sources
Severity
4.6MEDIUM
EPSS
0.0%
top 91.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 17

Description

Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the Google account.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p9_lite_firmwarevns-l21c185
NVDhuawei/p9_firmware4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-vc8h-576h-jh5w: Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass2022-05-17
CVEList
CVE-2016-8776: Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass2017-04-02

💬Community

1
Bugzilla
CVE-2015-8776 glibc: Segmentation fault caused by passing out-of-range data to strftime()2016-01-20
CVE-2016-8776 (MEDIUM CVSS 4.6) | Huawei P9 phones with software EVA- | cvebase.io