CVE-2017-8154
Last modified
CVE-2017-8154 is a vulnerability of currently unknown severity. The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 8 Lite Firmware | < prague-l31c530b160 |
| Huawei | Honor 8 Lite Firmware | < prague-l31c576b172 |
| Huawei | Honor 8 Lite Firmware | < prague-l31c432b180 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8154?
How severe is CVE-2017-8154?
How do I fix CVE-2017-8154?
Are you affected by CVE-2017-8154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
