PT-2018-6455 · Huawei · Huawei Mate 9 Pro

Publicado

2018-03-09

·

Atualizado

2018-03-27

·

CVE-2017-17225

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Huawei Mate 9 Pro versions before LON-AL00B 8.0.0.340a(C00)
Description: The issue is related to a buffer overflow in the Near Field Communication (NFC) module due to insufficient input validation. This could allow an attacker to inject malicious data into a target mobile phone using an NFC card reader or another device. A successful exploit may result in system restart or arbitrary code execution.
Recommendations: For versions before LON-AL00B 8.0.0.340a(C00), update to version LON-AL00B 8.0.0.340a(C00) or later to resolve the issue. As a temporary workaround, consider disabling the NFC module until a patch is available. Restrict access to the NFC functionality to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17225

Produtos afetados

Huawei Mate 9 Pro