PT-2017-18212 · Huawei · Huawei Smartphone

Dingbaozeng

+2

·

Published

2017-11-22

·

Updated

2017-12-06

·

CVE-2017-8208

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei smart phones versions earlier than NEM-AL10C00B356 Huawei smart phones versions earlier than Berlin-L21HNC432B360
Description The issue is caused by a buffer overflow due to the lack of parameter validation in the driver. An attacker can trick a user into installing a malicious APP with root privilege, which can send a specific parameter to the driver, potentially causing a system reboot or arbitrary code execution.
Recommendations For versions earlier than NEM-AL10C00B356, update to a version NEM-AL10C00B356 or later to resolve the issue. For versions earlier than Berlin-L21HNC432B360, update to a version Berlin-L21HNC432B360 or later to resolve the issue. As a temporary workaround, consider restricting the installation of APPs with root privilege to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8208

Affected Products

Huawei Smartphone