CVE-2016-4575

UnknownEPSS 0.71%

Last modified

CVE-2016-4575 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.

Metrics

EPSS Probability
0.71%

48.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiAth Firmwareal00c00
HuaweiAth Firmwarecl00c92
HuaweiAth Firmwaretl00hc01
HuaweiAth Firmwareul00c00
HuaweiAthAll versions
HuaweiRio Firmwareal00c00
HuaweiPlk Firmwareal10c00
HuaweiPlk Firmwareal10c92
HuaweiCherryplus Firmwaretl00c00
HuaweiCherryplus Firmwaretl00mc01
HuaweiCherryplus Firmwareul00c00
HuaweiCherryplusAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-4575?
Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.
How severe is CVE-2016-4575?
Severity scoring for CVE-2016-4575 is pending analysis. The EPSS model estimates a 0.71% probability of exploitation in the next 30 days.
How do I fix CVE-2016-4575?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-4575?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST