CVE-2017-8149
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an out-of-bounds memory access vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. the APP can modify specific data to cause buffer overflow in the next system reboot, causing out-of-bounds memory read which can continuous system reboot.
Affected (3)
Products: Huawei: P10 Firmware, P10 Plus Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before victoria-l09ac605b162 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before victoria-l29ac605b162 |
| Running on/with | Platform Versions |
|---|---|
Huawei P10 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before vicky-l29ac605b162 |
| Running on/with | Platform Versions |
|---|---|
Huawei P10 Plus | All versions |
References (2)
Source: psirt@huawei.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Timeline
No history available yet.