PT-2017-18153 · Huawei · Honor 8 Lite+4
Erez Yalon
·
Published
2017-11-22
·
Updated
2019-10-03
·
CVE-2017-8144
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Honor 5A versions before CAM-L03C605B143CUSTC605D003
Honor 8 Lite versions before Prague-L03C605B161
Honor 8 Lite versions before Prague-L23C605B160
Mate9 versions before MHA-AL00C00B225
Mate9 versions before LON-AL00C00B225
P10 versions before VTR-AL00C00B167
P10 versions before VTR-TL00C01B167
P10 Plus versions before VKY-AL00C00B167
P10 Plus versions before VKY-TL00C01B167
Description
The issue is related to a resource exhaustion vulnerability due to a configuration setting. An attacker may trick a user into installing a malicious application, which can then turn on the device's flash-light and rapidly drain the device battery.
Recommendations
For Honor 5A versions before CAM-L03C605B143CUSTC605D003, update to version CAM-L03C605B143CUSTC605D003 or later.
For Honor 8 Lite versions before Prague-L03C605B161, update to version Prague-L03C605B161 or later.
For Honor 8 Lite versions before Prague-L23C605B160, update to version Prague-L23C605B160 or later.
For Mate9 versions before MHA-AL00C00B225, update to version MHA-AL00C00B225 or later.
For Mate9 versions before LON-AL00C00B225, update to version LON-AL00C00B225 or later.
For P10 versions before VTR-AL00C00B167, update to version VTR-AL00C00B167 or later.
For P10 versions before VTR-TL00C01B167, update to version VTR-TL00C01B167 or later.
For P10 Plus versions before VKY-AL00C00B167, update to version VKY-AL00C00B167 or later.
For P10 Plus versions before VKY-TL00C01B167, update to version VKY-TL00C01B167 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Honor 5A
Honor 8 Lite
Mate 9
P10
P10 Plus