Directory Traversal Vulnerability in Huawei Mate 9 Smartphones
CVE-2017-2706

7.1HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The Huawei Mate 9 smartphone, particularly the model with software version MHA-AL00AC00B125, has a directory traversal vulnerability found in its Push module. This vulnerability arises because the system fails to validate the file name during decompression processes, allowing unauthorized access to system directories. An attacker may exploit this oversight to replace critical system files, potentially disrupting services and compromising device integrity. To mitigate risks, users are advised to ensure their devices are updated with the latest security patches from Huawei.

Affected Version(s)

Mate 9 MHA-AL00AC00B125

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.