Buffer Overflow Vulnerability in Huawei Mate 9 Pro's NFC Module
CVE-2017-17225

8.8HIGH

Key Information:

Vendor
McAfee
Vendor
CVE Published:
9 March 2018

Summary

The NFC module in Huawei Mate 9 Pro devices released before version LON-AL00B 8.0.0.340a(C00) is susceptible to a buffer overflow vulnerability caused by inadequate input validation. An attacker leveraging this flaw can exploit NFC functionalities using a malicious card reader or similar device. The exploitation could result in a system restart or allow the execution of arbitrary code on the affected device, posing risks to user security and privacy. For further information and security advice, please refer to Huawei's official advisory.

Affected Version(s)

Mate 9 Pro The versions before LON-AL00B 8.0.0.340a(C00)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.