Lucene search

K
cve[email protected]CVE-2018-7992
HistoryJul 31, 2018 - 2:29 p.m.

CVE-2018-7992

2018-07-3114:29:01
CWE-119
web.nvd.nist.gov
21
cve-2018-7992
huawei
mediapad m3
btv-w09c128b353custc128d001
mate 9 pro
p10 plus
buffer overflow
denial of service
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.5%

Mdapt Driver of Huawei MediaPad M3 BTV-W09C128B353CUSTC128D001; Mate 9 Pro versions earlier than 8.0.0.356(C00); P10 Plus versions earlier than 8.0.0.357(C00) has a buffer overflow vulnerability. The driver does not sufficiently validate the input, an attacker could trick the user to install a malicious application which would send crafted parameters to the driver. Successful exploit could cause a denial of service condition.

Affected configurations

NVD
Node
huaweimediapad_m3_firmwareMatchbtv-w09c128b353custc128d001
AND
huaweimediapad_m3Match-
Node
huaweimate_9_pro_firmwareRange<8.0.0.356\(c00\)
AND
huaweimate_9_proMatch-
Node
huaweip10_plus_firmwareRange<8.0.0.357\(c00\)
AND
huaweip10_plusMatch-
Node
huaweimate_9_firmwareRange<8.0.0.356\(c00\)
AND
huaweimate_9Match-

CNA Affected

[
  {
    "product": "MediaPad M3; Mate 9 Pro; P10 Plus",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "MediaPad M3 BTV-W09C128B353CUSTC128D001"
      },
      {
        "status": "affected",
        "version": "Mate 9 Pro versions earlier than 8.0.0.356(C00)"
      },
      {
        "status": "affected",
        "version": "P10 Plus versions earlier than 8.0.0.357(C00)"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.5%

Related for CVE-2018-7992