5.3
CVE-2017-8154
- EPSS 0.06%
- Veröffentlicht 11.04.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:33:25
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c530b160
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c576b172
Huawei ≫ Honor 8 Lite Firmware Version < prague-l31c432b180
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.142 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.