Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
Berlin-l21hn
Subscribe
Berlin-l21hn Firmware
Subscribe
Prague-al00a
Subscribe
Prague-al00a Firmware
Subscribe
Prague-al00b
Subscribe
Prague-al00b Firmware
Subscribe
Prague-al00c
Subscribe
Prague-al00c Firmware
Subscribe
Prague-l31
Subscribe
Prague-l31 Firmware
Subscribe
Prague-tl00a
Subscribe
Prague-tl00a Firmware
Subscribe
Prague-tl10a
Subscribe
Prague-tl10a Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8324 | Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T20:43:59.933Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2017-17158
No data.
Status : Modified
Published: 2018-05-24T14:29:00.250
Modified: 2024-11-21T03:17:36.397
Link: CVE-2017-17158
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD