5.4
CVE-2017-2713
- EPSS 0.03%
- Veröffentlicht 22.11.2017 19:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@huawei.com
- CVE-Watchlists
- Unerledigt
HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability. An attacker could exploit this vulnerability to tamper with air interface signaling messages and obtain some communication information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P9 Firmware Version < eva-l09c432b383
Huawei ≫ P9 Firmware Version < eva-l09c636b380
Huawei ≫ P9 Firmware Version < vie-l09c432b370
Huawei ≫ P9 Firmware Version < vie-l29c636b370
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.064 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| nvd@nist.gov | 4.8 | 6.5 | 4.9 |
AV:A/AC:L/Au:N/C:P/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.