8.8
CVE-2017-17224
- EPSS 0.06%
- Published 12.11.2019 22:15:10
- Last modified 21.11.2024 03:17:41
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Hg655m Firmware Version < harry-al00c_9.1.0.206\(c00e205r3p1\)
Huawei ≫ Hg655m Firmware Version < v100r001c02b023
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.163 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.