9.3

CVE-2017-8159

Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.

Data is provided by the National Vulnerability Database (NVD)
HuaweiAgassi-l09hn Firmware Versionags-l09c233b019
   HuaweiAgassi-l09hn Version-
HuaweiAgassi-w09hn Firmware Versionags-w09c233b019
   HuaweiAgassi-w09hn Version-
HuaweiKobe-l09ahn Firmware Versionkob-l09c233b017
   HuaweiKobe-l09ahn Version-
HuaweiKobe-w09chn Firmware Versionkob-w09c233b012
   HuaweiKobe-w09chn Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.382
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-704 Incorrect Type Conversion or Cast

The product does not correctly convert an object, resource, or structure from one type to a different type.