PT-2018-6433 · Google+1 · Android+2

Published

2018-10-17

·

Updated

2019-10-03

·

CVE-2017-17176

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Huawei Mate 9 versions earlier than MHA-AL00BC00B156 Huawei Mate 9 Pro versions earlier than MHA-CL00BC00B156 Huawei Mate 9 versions earlier than MHA-DL00BC00B156 Huawei Mate 9 versions earlier than MHA-TL00BC00B156 Huawei Mate 9 versions earlier than LON-AL00BC00B156 Huawei Mate 9 Pro versions earlier than LON-CL00BC00B156 Huawei Mate 9 versions earlier than LON-DL00BC00B156 Huawei Mate 9 versions earlier than LON-TL00BC00B156
Description: The hardware security module of the affected devices has an arbitrary memory read/write issue due to inadequate input parameters validation. An attacker with root privilege of the Android system could exploit this to read and write memory data or execute arbitrary code in the TrustZone.
Recommendations: For versions earlier than MHA-AL00BC00B156, update to version MHA-AL00BC00B156 or later. For versions earlier than MHA-CL00BC00B156, update to version MHA-CL00BC00B156 or later. For versions earlier than MHA-DL00BC00B156, update to version MHA-DL00BC00B156 or later. For versions earlier than MHA-TL00BC00B156, update to version MHA-TL00BC00B156 or later. For versions earlier than LON-AL00BC00B156, update to version LON-AL00BC00B156 or later. For versions earlier than LON-CL00BC00B156, update to version LON-CL00BC00B156 or later. For versions earlier than LON-DL00BC00B156, update to version LON-DL00BC00B156 or later. For versions earlier than LON-TL00BC00B156, update to version LON-TL00BC00B156 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17176

Affected Products

Android
Huawei Mate 9
Huawei Mate 9 Pro