CVE-2017-2691 describes a lock-screen bypass vulnerability affecting specific Huawei P9 firmware versions. An unauthenticated attacker with physical access can force the device into fastboot mode, delete the user's password file during reboot, and then gain unauthorized access without the screen lock password. This vulnerability is rated as Medium severity (CVSS 6.8) due to its physical attack vector, low complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< eva-tl00c01b373CPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | ||
< eva-dl00c17b373CPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | ||
< eva-cl00c92b373CPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | ||
< eva-al10c00b373CPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.