5.3
CVE-2017-8154
- EPSS 0.06%
- Published 11.04.2018 17:29:00
- Last modified 21.11.2024 03:33:25
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c530b160
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c576b172
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c432b180
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.142 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.