CVE Feed

    Dashboard / CVE / CVE-2017-2708

    CVE-2017-2708

    The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone' function, an attacker may exploit the vulnerability to bypass the 'Find Phone' function in order to use the phone normally.

    Published:Nov 22, 2017
    Last Modified:Apr 20, 2025
    EPS:Nov 22, 2017
    EPSS Score:0.00261
    CVSS Score:4.6

    Affected Products

    Vendor
    Huawei
    Product
    Nice
    Vendor
    Huawei
    Product
    Nice Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High