CVE-2017-17159
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.
Affected (5)
Products: Huawei: Mt8 Emui4.1 Firmware, Nts Al00 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version nxt-al10c00b386 |
| Running on/with | Platform Versions |
|---|---|
Huawei Mt8 Emui4.1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version nts-al00c00b535 |
| Running on/with | Platform Versions |
|---|---|
Huawei Nts Al00 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.