CVE-2017-17279 is an authentication bypass vulnerability in the soundtrigger module of Huawei Mate 9 Pro smartphones running software versions prior to LON-AL00B 8.0.0.343(C00). An attacker can trick a user into installing a malicious application, which then exploits this design flaw. This allows the attacker to bypass authentication and remotely control the phone to send short messages and make calls within audio range. Rated as Medium severity (CVSS 5.5), the vulnerability requires user interaction (UI:R) to install a malicious application, but once installed, it grants high integrity impact (I:H) to the attacker. The attack vector is local (AV:L) and has low attack complexity (AC:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability. Its EPSS score is very low, indicating a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< lon-al00b_8.0.0.343\(c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:mate_9_pro_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.