PT-2018-6420 · Huawei · Huawei Smartphone
Published
2018-05-24
·
Updated
2018-06-26
·
CVE-2017-17158
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Huawei smart phones versions before Berlin-L21HNC185B381
Huawei smart phones versions before Prague-AL00AC00B223
Huawei smart phones versions before Prague-AL00BC00B223
Huawei smart phones versions before Prague-AL00CC00B223
Huawei smart phones versions before Prague-L31C432B208
Huawei smart phones versions before Prague-TL00AC01B223
Description:
The issue allows an unauthenticated attacker to potentially expose information on a user's smart phone by sending specially crafted messages when the phone is connected to a malicious device for charging. This is due to insufficient input validation of the messages.
Recommendations:
For versions before Berlin-L21HNC185B381, update to a version after Berlin-L21HNC185B381 to resolve the issue.
For versions before Prague-AL00AC00B223, update to a version after Prague-AL00AC00B223 to resolve the issue.
For versions before Prague-AL00BC00B223, update to a version after Prague-AL00BC00B223 to resolve the issue.
For versions before Prague-AL00CC00B223, update to a version after Prague-AL00CC00B223 to resolve the issue.
For versions before Prague-L31C432B208, update to a version after Prague-L31C432B208 to resolve the issue.
For versions before Prague-TL00AC01B223, update to a version after Prague-TL00AC01B223 to resolve the issue.
As a temporary workaround, consider restricting connections to trusted devices to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Smartphone