CVE-2017-8150
Last modified
CVE-2017-8150 is a vulnerability of currently unknown severity. The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause arbitrary memory writing in the next system reboot, causing continuous system reboot or arbitrary code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | P10 Firmware | < victoria-l09ac605b162 |
| Huawei | P10 Firmware | < victoria-l29ac605b162 |
| Huawei | P10 Plus Firmware | < vicky-l29ac605b162 |
| Huawei | P8 Lite Firmware | < ale-l21c113b566 |
| Huawei | P9 Firmware | < eva-l09c432b391 |
| Huawei | P9 Firmware | < eva-l09c576b386 |
| Huawei | P9 Firmware | < eva-l09c605b390 |
| Huawei | P9 Firmware | < eva-l09c635b387 |
| Huawei | P9 Firmware | < eva-l09c636b388 |
| Huawei | P9 Firmware | < eva-l19c10b390 |
| Huawei | P9 Firmware | < eva-l19c432b388 |
| Huawei | P9 Firmware | < eva-l19c605b390 |
| Huawei | P9 Firmware | < eva-l19c636b391 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-02-smartphone-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-02-smartphone-enIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8150?
How severe is CVE-2017-8150?
How do I fix CVE-2017-8150?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8144Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei sm…
- CVE-2017-8145The call module of P10 and P10 Plus smartphones with softwar…
- CVE-2017-8146The call module of P10 and P10 Plus smartphones with softwar…
- CVE-2017-8147AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 wit…
- CVE-2017-8148Audio driver in P9 smartphones with software The versions be…
- CVE-2017-8149The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8151Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8152Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8153Huawei VMall (for Android) with the versions before 1.5.8.5 …
- CVE-2017-8154The Themes App Honor 8 Lite Huawei mobile phones with softwa…
- CVE-2017-8155The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8156The outdoor unit of Customer Premise Equipment (CPE) product…
Are you affected by CVE-2017-8150?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
