5.5

CVE-2017-8146

The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.

Data is provided by the National Vulnerability Database (NVD)
HuaweiP10 Firmware Version < vtr-al00c00b167
   HuaweiP10 Version-
HuaweiP10 Plus Firmware Version < vky-al00c00b167
   HuaweiP10 Plus Version-
HuaweiP10 Firmware Version < vtr-tl00c01b167
   HuaweiP10 Version-
HuaweiP10 Plus Firmware Version < vky-tl00c01b167
   HuaweiP10 Plus Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.2
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.