PT-2018-6455 · Huawei · Huawei Mate 9 Pro
Published
2018-03-09
·
Updated
2018-03-27
·
CVE-2017-17225
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Huawei Mate 9 Pro versions before LON-AL00B 8.0.0.340a(C00)
Description:
The issue is related to a buffer overflow in the Near Field Communication (NFC) module due to insufficient input validation. This could allow an attacker to inject malicious data into a target mobile phone using an NFC card reader or another device. A successful exploit may result in system restart or arbitrary code execution.
Recommendations:
For versions before LON-AL00B 8.0.0.340a(C00), update to version LON-AL00B 8.0.0.340a(C00) or later to resolve the issue. As a temporary workaround, consider disabling the NFC module until a patch is available. Restrict access to the NFC functionality to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Mate 9 Pro