PT-2017-18153 · Huawei · Honor 8 Lite+4

Erez Yalon

·

Published

2017-11-22

·

Updated

2019-10-03

·

CVE-2017-8144

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Honor 5A versions before CAM-L03C605B143CUSTC605D003 Honor 8 Lite versions before Prague-L03C605B161 Honor 8 Lite versions before Prague-L23C605B160 Mate9 versions before MHA-AL00C00B225 Mate9 versions before LON-AL00C00B225 P10 versions before VTR-AL00C00B167 P10 versions before VTR-TL00C01B167 P10 Plus versions before VKY-AL00C00B167 P10 Plus versions before VKY-TL00C01B167
Description The issue is related to a resource exhaustion vulnerability due to a configuration setting. An attacker may trick a user into installing a malicious application, which can then turn on the device's flash-light and rapidly drain the device battery.
Recommendations For Honor 5A versions before CAM-L03C605B143CUSTC605D003, update to version CAM-L03C605B143CUSTC605D003 or later. For Honor 8 Lite versions before Prague-L03C605B161, update to version Prague-L03C605B161 or later. For Honor 8 Lite versions before Prague-L23C605B160, update to version Prague-L23C605B160 or later. For Mate9 versions before MHA-AL00C00B225, update to version MHA-AL00C00B225 or later. For Mate9 versions before LON-AL00C00B225, update to version LON-AL00C00B225 or later. For P10 versions before VTR-AL00C00B167, update to version VTR-AL00C00B167 or later. For P10 versions before VTR-TL00C01B167, update to version VTR-TL00C01B167 or later. For P10 Plus versions before VKY-AL00C00B167, update to version VKY-AL00C00B167 or later. For P10 Plus versions before VKY-TL00C01B167, update to version VKY-TL00C01B167 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8144

Affected Products

Honor 5A
Honor 8 Lite
Mate 9
P10
P10 Plus