7.1

CVE-2016-8794

Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before CRR-TL00C01B368, Versions before CRR-UL00C00B368, Versions before CRR-UL20C00B368; and P8 phones with software Versions before GRA-TL00C01B366, Versions before GRA-CL00C92B366, Versions before GRA-CL10C92B366, Versions before GRA-UL00C00B366, Versions before GRA-UL10C00B366 allow attackers with graphic or Camera privilege to crash the system or escalate privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Mate S Firmware Version -
   Huawei ≫ Mate S Version -
Huawei ≫ Mate 8 Firmware Version -
   Huawei ≫ Mate 8 Version -
Huawei ≫ P8 Firmware Version -
   Huawei ≫ P8 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.424
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.2 5.9
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
NIST 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-smartphone-en
Vendor Advisory
http://www.securityfocus.com/bid/94404
Third Party Advisory
VDB Entry