9.3
CVE-2017-8159
- EPSS 0.19%
- Published 22.11.2017 19:29:03
- Last modified 20.04.2025 01:37:25
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Agassi-l09hn Firmware Versionags-l09c233b019
Huawei ≫ Agassi-w09hn Firmware Versionags-w09c233b019
Huawei ≫ Kobe-l09ahn Firmware Versionkob-l09c233b017
Huawei ≫ Kobe-w09chn Firmware Versionkob-w09c233b012
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.382 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-704 Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.