CVE-2017-2715

HIGH

Huawei Files < 7.1.1.309 - Unauthorized Sensitive Information Exposure via Safe Key Database

Title source: llm
STIX 2.1

Description

The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper design of the Safe key database. An unauthorized attacker could access sensitive database information and may crack users' Safe passwords, leading to information leak.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 8.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (2)
huawei/files < 7.1.1.309
Huawei Technologies Co., Ltd./Files &#xa3;&#xa8;Files is the smartphone APP&#xa3;&#xa9; 7.1.1.309 and earlier versions
Published Nov 22, 2017
Tracked Since Feb 18, 2026