CVE-2017-2727
4.3
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 0.9 / Impact: 3.4
Source: NVD
Description
Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privilege escalation vulnerability. An unauthenticated attacker can bypass phone activation to user management page of the phone and create a new user. Successful exploit could allow the attacker operate part function of the phone.
Affected (5)
Products: Huawei: P9 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before eva-al00c00b365 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before eva-al10c00b365 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before eva-cl00c92b365 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before eva-dl00c17b365 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before eva-tl00c01b365 |
| Running on/with | Platform Versions |
|---|---|
Huawei P9 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.