Integer Overflow Vulnerability in Huawei Smartphones
CVE-2017-17328

5.5MEDIUM

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
9 March 2018

Summary

Huawei smartphones running specific software versions are susceptible to an integer overflow vulnerability that arises from improper handling of certain variables during processing. Attackers may exploit this flaw by deceiving users with root privileges into installing a malicious application, potentially leading to unauthorized access and information disclosure.

Affected Version(s)

MHA-AL00A MHA-AL00AC00B125

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.