CVE-2017-8154
Last modified
CVE-2017-8154 is a vulnerability of currently unknown severity. The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 8 Lite Firmware | < prague-l31c530b160 |
| Huawei | Honor 8 Lite Firmware | < prague-l31c576b172 |
| Huawei | Honor 8 Lite Firmware | < prague-l31c432b180 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8154?
How severe is CVE-2017-8154?
How do I fix CVE-2017-8154?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8148Audio driver in P9 smartphones with software The versions be…
- CVE-2017-8149The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8150The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8151Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8152Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8153Huawei VMall (for Android) with the versions before 1.5.8.5 …
- CVE-2017-8155The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8156The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8157OceanStor 5800 V3 with software V300R002C00 and V300R002C10,…
- CVE-2017-8158FusionCompute V100R005C00 and V100R005C10 have an improper a…
- CVE-2017-8159Some Huawei smartphones with software AGS-L09C233B019,AGS-W0…
- CVE-2017-8160The Madapt Driver of some Huawei smart phones with software …
Are you affected by CVE-2017-8154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
