5.5
CVE-2017-17140
- EPSS 0.11%
- Veröffentlicht 05.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:33
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Enjoy 5s Firmware Version < tag-al00c92b170
Huawei ≫ Y6 Pro Firmware Version < tit-l01c576b121
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.256 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.