PT-2017-13989 · Huawei · Huawei Mate 10 Pro+3
Published
2017-12-22
·
Updated
2018-01-09
·
CVE-2017-15311
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei Mate 10 versions before 8.0.0.120(SP2C00)
Huawei Mate 10 Pro versions before 8.0.0.120(SP2C00)
Huawei Mate 9 versions before 8.0.0.334(C00)
Huawei Mate 9 Pro versions before 8.0.0.334(C00)
Description
The baseband modules of the affected Huawei smart phones have a stack overflow issue due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range using a special wireless device, leading to a stack overflow when the baseband module handles these packets. This could allow the attacker to perform a denial of service attack or achieve remote code execution in the baseband module.
Recommendations
For Huawei Mate 10 versions before 8.0.0.120(SP2C00), update to version 8.0.0.120(SP2C00) or later.
For Huawei Mate 10 Pro versions before 8.0.0.120(SP2C00), update to version 8.0.0.120(SP2C00) or later.
For Huawei Mate 9 versions before 8.0.0.334(C00), update to version 8.0.0.334(C00) or later.
For Huawei Mate 9 Pro versions before 8.0.0.334(C00), update to version 8.0.0.334(C00) or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Mate 10
Huawei Mate 10 Pro
Huawei Mate 9
Huawei Mate 9 Pro