Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20170306-01-SMARTPHONE
HistoryMar 06, 2017 - 12:00 a.m.

Security Advisory - Arbitrary Memory Read Write Vulnerability in Huawei Smart Phones

2017-03-0600:00:00
Huawei Technologies
www.huawei.com
32

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

12.8%

There is a arbitrary memory read/write vulnerability in the hardware security module of some Huawei smart phones due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone. (Vulnerability ID: HWPSIRT-2017-01060)

This vulnerability has been assigned a CVE ID: CVE-2017-17176.
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170306-01-smartphone-en

Affected configurations

Vulners
Node
huaweimate_9_proMatchmha-al00bc00b156
OR
huaweimate_9_proMatchmha-cl00bc00b156
OR
huaweimate_9_proMatchmha-dl00bc00b156
OR
huaweimate_9_proMatchmha-tl00bc00b156
OR
huaweimate_9_proMatchlon-al00bc00b156
OR
huaweimate_9_proMatchlon-cl00bc00b156
OR
huaweimate_9_proMatchlon-dl00bc00b156
OR
huaweimate_9_proMatchlon-tl00bc00b156

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

12.8%

Related for HUAWEI-SA-20170306-01-SMARTPHONE