6.3

CVE-2017-17171

Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters. An attacker may trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions. Successful exploit could allow the app to send specific parameters to the smart phone driver, which will result in system restart.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HuaweiMate 8 Firmware Version < nxt-al10c00b593
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-cl00c92b593
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-dl00c17b593
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l09c636b598a
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l09c185b583
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l09c432b582
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l09c605b585custc605d590
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l29c10b583
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l29c185b585
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxt-l29c636b594a
   HuaweiMate 8 Version-
HuaweiMate 8 Firmware Version < nxtl00c01b593
   HuaweiMate 8 Version-
HuaweiP9 Firmware Version < eva-al00c00b398
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-al10c00b398
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-cl00c92b398
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-dl00c17b398
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l09c185b391
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l09c432b395
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l09c464b383
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l09c605b392
   HuaweiP9 Version-
HuaweiP9 Firmware Version <= eva-l09c636b388
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l19c10b394
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l19c432b392
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l19c605b390
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l19c636b393
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-l29c636b389
   HuaweiP9 Version-
HuaweiP9 Firmware Version < eva-tl00c01b398
   HuaweiP9 Version-
HuaweiP9 Plus Firmware Version < vie-l09c318b182
   HuaweiP9 Plus Version-
HuaweiP9 Plus Firmware Version < vie-l09c432b380
   HuaweiP9 Plus Version-
HuaweiP9 Plus Firmware Version < vie-l09c576b180
   HuaweiP9 Plus Version-
HuaweiP9 Plus Firmware Version < vie-l29c605b370
   HuaweiP9 Plus Version-
HuaweiP9 Plus Firmware Version < vie-l29c636b388
   HuaweiP9 Plus Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.2 0.6 3.6
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 6.3 6.8 6.9
AV:N/AC:M/Au:S/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.