Insufficient Input Validation in Huawei Mobile Phones
CVE-2017-8175

5.5MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
22 November 2017

Summary

The Bastet component of select Huawei mobile phones suffers from an insufficient input validation issue, arising from a failure to properly validate parameters. This flaw enables an attacker to deceive users into installing malicious applications. Once installed, the malicious app is capable of altering specific system parameters, which may lead to an unexpected system reboot, posing a significant risk to the integrity and availability of the affected devices.

Affected Version(s)

Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 Earlier than Vicky-AL00AC00B167 versions,Earlier than Victoria-AL00AC00B167 versions,Earlier than Warsaw-AL00C00B191 versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.