PT-2017-15522 · Huawei · Tit-Al00
Publicado
2017-11-22
·
Atualizado
2017-12-11
·
CVE-2017-2735
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIT-AL00 smartphones with software versions earlier than TIT-AL00C583B214
Description
The issue concerns an exposed system interface in the software, which is used for interaction with external applications. However, the software does not properly restrict access to this interface. As a result, an attacker could potentially trick a user into installing a malicious application that calls the interface, allowing the attacker to modify system properties.
Recommendations
For TIT-AL00 smartphones with software versions earlier than TIT-AL00C583B214, update to a version TIT-AL00C583B214 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tit-Al00