PT-2017-15491 · Huawei · Smarthome+12

Published

2017-11-22

·

Updated

2020-04-02

·

CVE-2017-2704

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smarthome versions 1.0.2.364 and earlier HiAPP versions 7.3.0.303 and earlier HwParentControl versions 2.0.0 and earlier HwParentControlParent versions 5.1.0.12 and earlier Crowdtest versions 1.5.3 and earlier HiWallet versions 8.0.0.301 and earlier Huawei Pay versions 8.0.0.300 and earlier Skytone versions 8.1.2.300 and earlier HwCloudDrive(EMUI6.0) versions 8.0.0.307 and earlier HwPhoneFinder(EMUI6.0) versions 9.3.0.310 and earlier HwPhoneFinder(EMUI5.1) versions 9.2.2.303 and earlier HiCinema versions 8.0.2.300 and earlier HuaweiWear versions 21.0.0.360 and earlier HiHealthApp versions 3.0.3.300 and earlier
Description The issue concerns an information exposure vulnerability where encryption keys are stored in the system, allowing an attacker to obtain these keys through reverse engineering, resulting in information exposure.
Recommendations For Smarthome versions 1.0.2.364 and earlier, update to a version later than 1.0.2.364. For HiAPP versions 7.3.0.303 and earlier, update to a version later than 7.3.0.303. For HwParentControl versions 2.0.0 and earlier, update to a version later than 2.0.0. For HwParentControlParent versions 5.1.0.12 and earlier, update to a version later than 5.1.0.12. For Crowdtest versions 1.5.3 and earlier, update to a version later than 1.5.3. For HiWallet versions 8.0.0.301 and earlier, update to a version later than 8.0.0.301. For Huawei Pay versions 8.0.0.300 and earlier, update to a version later than 8.0.0.300. For Skytone versions 8.1.2.300 and earlier, update to a version later than 8.1.2.300. For HwCloudDrive(EMUI6.0) versions 8.0.0.307 and earlier, update to a version later than 8.0.0.307. For HwPhoneFinder(EMUI6.0) versions 9.3.0.310 and earlier, update to a version later than 9.3.0.310. For HwPhoneFinder(EMUI5.1) versions 9.2.2.303 and earlier, update to a version later than 9.2.2.303. For HiCinema versions 8.0.2.300 and earlier, update to a version later than 8.0.2.300. For HuaweiWear versions 21.0.0.360 and earlier, update to a version later than 21.0.0.360. For HiHealthApp versions 3.0.3.300 and earlier, update to a version later than 3.0.3.300.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2704

Affected Products

Crowdtest
Hiapp
Hicinema
Hihealthapp
Hiwallet
Huawei Pay
Huaweiwear
Hwclouddrive
Hwparentcontrol
Hwparentcontrolparent
Phone Finder
Skytone
Smarthome