PT-2017-13989 · Huawei · Huawei Mate 10 Pro+3

Published

2017-12-22

·

Updated

2018-01-09

·

CVE-2017-15311

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei Mate 10 versions before 8.0.0.120(SP2C00) Huawei Mate 10 Pro versions before 8.0.0.120(SP2C00) Huawei Mate 9 versions before 8.0.0.334(C00) Huawei Mate 9 Pro versions before 8.0.0.334(C00)
Description The baseband modules of the affected Huawei smart phones have a stack overflow issue due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range using a special wireless device, leading to a stack overflow when the baseband module handles these packets. This could allow the attacker to perform a denial of service attack or achieve remote code execution in the baseband module.
Recommendations For Huawei Mate 10 versions before 8.0.0.120(SP2C00), update to version 8.0.0.120(SP2C00) or later. For Huawei Mate 10 Pro versions before 8.0.0.120(SP2C00), update to version 8.0.0.120(SP2C00) or later. For Huawei Mate 9 versions before 8.0.0.334(C00), update to version 8.0.0.334(C00) or later. For Huawei Mate 9 Pro versions before 8.0.0.334(C00), update to version 8.0.0.334(C00) or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15311

Affected Products

Huawei Mate 10
Huawei Mate 10 Pro
Huawei Mate 9
Huawei Mate 9 Pro