Buffer Overflow Vulnerability in Huawei P10 Smart Phones
CVE-2017-2725
7.8HIGH
Summary
A buffer overflow vulnerability exists in the Bastet application on Huawei P10 Plus and P10 smartphones, affecting software versions prior to VKY-AL00C00B123 and VTR-AL00C00B123. This vulnerability allows an attacker with root privileges on an Android system to deceive users into installing a malicious application. Once installed, the malicious app can manipulate specific data, leading to a buffer overflow during the next system reboot. The exploitation of this vulnerability may result in continuous system reboots or arbitrary code execution, compromising device integrity and user data.
Affected Version(s)
P10 Plus,P10 Eariler than VKY-AL00C00B123 verisons,Earlier than VTR-AL00C00B123 versions
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved