PT-2018-6409 · Huawei · Huawei Y6 Pro+1

Mateusz Fruba

·

Publicado

2018-03-05

·

Atualizado

2018-03-27

·

CVE-2017-17140

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Huawei Enjoy 5s versions prior to TAG-AL00C92B170 Huawei Y6 Pro versions prior to TIT-L01C576B121
Description: The issue is caused by a lack of parameter validation, leading to an information leak. An attacker can trick a user into installing a malicious application, which can then read sensitive information in kernel memory, potentially causing a sensitive information leak.
Recommendations: For Huawei Enjoy 5s versions prior to TAG-AL00C92B170, update to version TAG-AL00C92B170 or later to resolve the issue. For Huawei Y6 Pro versions prior to TIT-L01C576B121, update to version TIT-L01C576B121 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17140

Produtos afetados

Huawei Enjoy 5S
Huawei Y6 Pro