PT-2018-6455 · Huawei · Huawei Mate 9 Pro
Publicado
2018-03-09
·
Atualizado
2018-03-27
·
CVE-2017-17225
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Huawei Mate 9 Pro versions before LON-AL00B 8.0.0.340a(C00)
Description:
The issue is related to a buffer overflow in the Near Field Communication (NFC) module due to insufficient input validation. This could allow an attacker to inject malicious data into a target mobile phone using an NFC card reader or another device. A successful exploit may result in system restart or arbitrary code execution.
Recommendations:
For versions before LON-AL00B 8.0.0.340a(C00), update to version LON-AL00B 8.0.0.340a(C00) or later to resolve the issue. As a temporary workaround, consider disabling the NFC module until a patch is available. Restrict access to the NFC functionality to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Mate 9 Pro