PT-2018-6433 · Google+1 · Android+2
Published
2018-10-17
·
Updated
2019-10-03
·
CVE-2017-17176
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Huawei Mate 9 versions earlier than MHA-AL00BC00B156
Huawei Mate 9 Pro versions earlier than MHA-CL00BC00B156
Huawei Mate 9 versions earlier than MHA-DL00BC00B156
Huawei Mate 9 versions earlier than MHA-TL00BC00B156
Huawei Mate 9 versions earlier than LON-AL00BC00B156
Huawei Mate 9 Pro versions earlier than LON-CL00BC00B156
Huawei Mate 9 versions earlier than LON-DL00BC00B156
Huawei Mate 9 versions earlier than LON-TL00BC00B156
Description:
The hardware security module of the affected devices has an arbitrary memory read/write issue due to inadequate input parameters validation. An attacker with root privilege of the Android system could exploit this to read and write memory data or execute arbitrary code in the TrustZone.
Recommendations:
For versions earlier than MHA-AL00BC00B156, update to version MHA-AL00BC00B156 or later.
For versions earlier than MHA-CL00BC00B156, update to version MHA-CL00BC00B156 or later.
For versions earlier than MHA-DL00BC00B156, update to version MHA-DL00BC00B156 or later.
For versions earlier than MHA-TL00BC00B156, update to version MHA-TL00BC00B156 or later.
For versions earlier than LON-AL00BC00B156, update to version LON-AL00BC00B156 or later.
For versions earlier than LON-CL00BC00B156, update to version LON-CL00BC00B156 or later.
For versions earlier than LON-DL00BC00B156, update to version LON-DL00BC00B156 or later.
For versions earlier than LON-TL00BC00B156, update to version LON-TL00BC00B156 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Huawei Mate 9
Huawei Mate 9 Pro