5.5
CVE-2017-8183
- EPSS 0.11%
- Veröffentlicht 22.11.2017 19:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@huawei.com
- CVE-Watchlists
- Unerledigt
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access vulnerabilities, leading to sensitive information leakage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Mtk Platform Smart Phone Firmware Version < nice-al10c00b140
Huawei ≫ Mtk Platform Smart Phone Firmware Version < nice-al00c00b160
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.256 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.