CVE-2017-2699
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Affected (3)
Products: Huawei: Honor 7 Firmware, Mate S Firmware, Lyo L21 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before plk-ul00c17b385 |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor 7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before crr-l09c432b380 |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate S | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before lyo-l21c577b128 |
| Running on/with | Platform Versions |
|---|---|
Huawei Lyo L21 | All versions |
References (4)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.