Lucene search

K
cve[email protected]CVE-2014-8571
HistoryApr 02, 2017 - 8:59 p.m.

CVE-2014-8571

2017-04-0220:59:00
CWE-264
web.nvd.nist.gov
19
huawei
ascend p6
mobile phones
screen capture
root permission
user information
leakage
malware

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

4.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.4%

Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01B508SP02; EDGE-C00 V100R001C92B508SP02 and earlier versions before V100R001C92B508SP03 can capture screens without the root permission. As a result, user information can be leaked by malware on Ascend P6 mobile phones.

Affected configurations

NVD
Node
huaweiascend_p6_edge-u00_firmwareRangev100r001c17b508sp01
AND
huaweiascend_p6_edge-u00Match-
Node
huaweiascend_p6_edge-t00_firmwareRangev100r001c01b508sp01
AND
huaweiascend_p6_edge-t00Match-
Node
huaweiascend_p6_edge-c00_firmwareRangev100r001c92b508sp02
AND
huaweiascend_p6_edge-c00Match-

CNA Affected

[
  {
    "product": "EDGE-U00,EDGE-T00,EDGE-C00 EDGE-U00 V100R001C17B508SP01 and earlier versions,V100R001C17B508SP02,EDGE-T00 V100R001C01B508SP01 and earlier versions,V100R001C01B508SP02,EDGE-C00 V100R001C92B508SP02 and earlier versions,V100R001C92B508SP03",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "EDGE-U00,EDGE-T00,EDGE-C00 EDGE-U00 V100R001C17B508SP01 and earlier versions,V100R001C17B508SP02,EDGE-T00 V100R001C01B508SP01 and earlier versions,V100R001C01B508SP02,EDGE-C00 V100R001C92B508SP02 and earlier versions,V100R001C92B508SP03"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

4.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.4%

Related for CVE-2014-8571