PT-2018-8445 · Huawei · Huawei Honor 8 Lite
Erez Yalon
·
Published
2018-04-11
·
Updated
2019-10-03
·
CVE-2017-8154
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei Honor 8 Lite versions before Prague-L31C576B172
Huawei Honor 8 Lite versions before Prague-L31C530B160
Huawei Honor 8 Lite versions before Prague-L31C432B180
Description
The Themes App has a man-in-the-middle (MITM) issue due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this to tamper with downloaded themes.
Recommendations
For versions before Prague-L31C576B172, consider disabling the theme download feature until a secure update is available.
For versions before Prague-L31C530B160, restrict theme downloads to trusted sources to minimize the risk of exploitation.
For versions before Prague-L31C432B180, avoid using the theme download feature over unsecured networks until the issue is resolved.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Honor 8 Lite