← Back

CVE-2017-15311

nvd nist
Published: Dec 22, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker could exploit this vulnerability to perform a denial of service attack or remote code execution in baseband module.

Affected (4)

4 products
Mate 10 Firmware
Mate 10 Pro Firmware
Mate 9 Firmware
Mate 9 Pro Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before alp-al00_8.0.0.120\(sp2c00\)
Running on/withPlatform Versions
Huawei
Mate 10
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before bla-al00_8.0.0.120\(sp2c00\)
Running on/withPlatform Versions
Huawei
Mate 10 Pro
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before mha-al00b_8.0.0.334\(c00\)
Running on/withPlatform Versions
Huawei
Mate 9
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before lon-al00b_8.0.0.334\(c00\)
Running on/withPlatform Versions
Huawei
Mate 9 Pro
All versions

References (2)

Timeline

No history available yet.