Lucene search

K
cveMitreCVE-2015-8680
HistoryApr 07, 2016 - 8:59 p.m.

CVE-2015-8680

2016-04-0720:59:03
CWE-284
mitre
web.nvd.nist.gov
20
cve-2015-8680
huawei p8
mate s
graphics driver
denial of service
system crash
interface access control vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

33.4%

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an “interface access control vulnerability,” a different vulnerability than CVE-2015-8307.

Affected configurations

Nvd
Node
huaweip8Match-
AND
huaweip8_firmwareMatchgra-cl00
OR
huaweip8_firmwareMatchgra-cl10
OR
huaweip8_firmwareMatchgra-tl00
OR
huaweip8_firmwareMatchgra-ul00
OR
huaweip8_firmwareMatchgra-ul10
Node
huaweimate_sMatch-
AND
huaweimate_s_firmwareMatchcrr-cl00
OR
huaweimate_s_firmwareMatchcrr-tl00
OR
huaweimate_s_firmwareMatchcrr-ul00
VendorProductVersionCPE
huaweip8-cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
huaweip8_firmwaregra-cl00cpe:2.3:o:huawei:p8_firmware:gra-cl00:*:*:*:*:*:*:*
huaweip8_firmwaregra-cl10cpe:2.3:o:huawei:p8_firmware:gra-cl10:*:*:*:*:*:*:*
huaweip8_firmwaregra-tl00cpe:2.3:o:huawei:p8_firmware:gra-tl00:*:*:*:*:*:*:*
huaweip8_firmwaregra-ul00cpe:2.3:o:huawei:p8_firmware:gra-ul00:*:*:*:*:*:*:*
huaweip8_firmwaregra-ul10cpe:2.3:o:huawei:p8_firmware:gra-ul10:*:*:*:*:*:*:*
huaweimate_s-cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
huaweimate_s_firmwarecrr-cl00cpe:2.3:o:huawei:mate_s_firmware:crr-cl00:*:*:*:*:*:*:*
huaweimate_s_firmwarecrr-tl00cpe:2.3:o:huawei:mate_s_firmware:crr-tl00:*:*:*:*:*:*:*
huaweimate_s_firmwarecrr-ul00cpe:2.3:o:huawei:mate_s_firmware:crr-ul00:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

33.4%

Related for CVE-2015-8680