CVE-2017-8150
Last modified
CVE-2017-8150 is a vulnerability of currently unknown severity. The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause arbitrary memory writing in the next system reboot, causing continuous system reboot or arbitrary code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | P10 Firmware | < victoria-l09ac605b162 |
| Huawei | P10 Firmware | < victoria-l29ac605b162 |
| Huawei | P10 Plus Firmware | < vicky-l29ac605b162 |
| Huawei | P8 Lite Firmware | < ale-l21c113b566 |
| Huawei | P9 Firmware | < eva-l09c432b391 |
| Huawei | P9 Firmware | < eva-l09c576b386 |
| Huawei | P9 Firmware | < eva-l09c605b390 |
| Huawei | P9 Firmware | < eva-l09c635b387 |
| Huawei | P9 Firmware | < eva-l09c636b388 |
| Huawei | P9 Firmware | < eva-l19c10b390 |
| Huawei | P9 Firmware | < eva-l19c432b388 |
| Huawei | P9 Firmware | < eva-l19c605b390 |
| Huawei | P9 Firmware | < eva-l19c636b391 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-02-smartphone-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-02-smartphone-enIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8150?
How severe is CVE-2017-8150?
How do I fix CVE-2017-8150?
Are you affected by CVE-2017-8150?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
