5.5

CVE-2017-8146

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P10 Firmware Version < vtr-al00c00b167
   Huawei ≫ P10 Version -
Huawei ≫ P10 Plus Firmware Version < vky-al00c00b167
   Huawei ≫ P10 Plus Version -
Huawei ≫ P10 Firmware Version < vtr-tl00c01b167
   Huawei ≫ P10 Version -
Huawei ≫ P10 Plus Firmware Version < vky-tl00c01b167
   Huawei ≫ P10 Plus Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.411
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170725-02-smartphone-en
Vendor Advisory