PT-2018-6409 · Huawei · Huawei Y6 Pro+1

Mateusz Fruba

·

Published

2018-03-05

·

Updated

2018-03-27

·

CVE-2017-17140

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Huawei Enjoy 5s versions prior to TAG-AL00C92B170 Huawei Y6 Pro versions prior to TIT-L01C576B121
Description: The issue is caused by a lack of parameter validation, leading to an information leak. An attacker can trick a user into installing a malicious application, which can then read sensitive information in kernel memory, potentially causing a sensitive information leak.
Recommendations: For Huawei Enjoy 5s versions prior to TAG-AL00C92B170, update to version TAG-AL00C92B170 or later to resolve the issue. For Huawei Y6 Pro versions prior to TIT-L01C576B121, update to version TIT-L01C576B121 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17140

Affected Products

Huawei Enjoy 5S
Huawei Y6 Pro