Description
Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure.
Published: 2018-05-24
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-8324 Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure.
History

No history.

Subscriptions

Huawei Berlin-l21hn Berlin-l21hn Firmware Prague-al00a Prague-al00a Firmware Prague-al00b Prague-al00b Firmware Prague-al00c Prague-al00c Firmware Prague-l31 Prague-l31 Firmware Prague-tl00a Prague-tl00a Firmware Prague-tl10a Prague-tl10a Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-05T20:43:59.933Z

Reserved: 2017-12-04T00:00:00.000Z

Link: CVE-2017-17158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-24T14:29:00.250

Modified: 2024-11-21T03:17:36.397

Link: CVE-2017-17158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses