CVE-2017-8153
Last modified
CVE-2017-8153 is a vulnerability of currently unknown severity. Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. Successful exploit could lead to resource occupation or information leak.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Vmall | < 1.5.8.5 |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170901-01-smartphone-enIssue Tracking, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170901-01-smartphone-enIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8153?
How severe is CVE-2017-8153?
How do I fix CVE-2017-8153?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8147AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 wit…
- CVE-2017-8148Audio driver in P9 smartphones with software The versions be…
- CVE-2017-8149The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8150The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8151Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8152Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8154The Themes App Honor 8 Lite Huawei mobile phones with softwa…
- CVE-2017-8155The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8156The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8157OceanStor 5800 V3 with software V300R002C00 and V300R002C10,…
- CVE-2017-8158FusionCompute V100R005C00 and V100R005C10 have an improper a…
- CVE-2017-8159Some Huawei smartphones with software AGS-L09C233B019,AGS-W0…
Are you affected by CVE-2017-8153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
