National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2016-4575 Detail

Description

Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.

Source:  MITRE
Description Last Modified:  05/25/2016

Impact

CVSS v3.0 Severity and Metrics:

Base Score: 6.1 MEDIUM
Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (V3 legend)
Impact Score: 2.7
Exploitability Score: 2.8


Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope (S): Changed
Confidentiality (C): Low
Integrity (I): Low
Availability (A): None

CVSS v2.0 Severity and Metrics:

Base Score: 4.3 MEDIUM
Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N) (V2 legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6


Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (AU): None
Confidentiality (C): None
Integrity (I): Partial
Availability (A): None
Additional Information:
Victim must voluntarily interact with attack mechanism
Allows unauthorized modification

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160507-01-emailapp-en Vendor Advisory

Technical Details

Vulnerability Type (View All)

  • Cross-Site Scripting (XSS) (CWE-79)

Known Affected Software Configurations Switch to CPE 2.2

Configuration 1 ( hide )
AND
OR
 cpe:2.3:o:huawei:ath_firmware:al00c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:ath_firmware:cl00c92:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:ath_firmware:tl00hc01:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:ath_firmware:ul00c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
OR
 cpe:2.3:h:huawei:ath:-:*:*:*:*:*:*:*
     Show Matching CPE(s)

Configuration 2 ( hide )
 cpe:2.3:o:huawei:rio_firmware:al00c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
Running on/with
 cpe:2.3:h:huawei:rio:-:*:*:*:*:*:*:*
     Show Matching CPE(s)

Configuration 3 ( hide )
 cpe:2.3:o:huawei:plk_firmware:al10c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:plk_firmware:al10c92:*:*:*:*:*:*:*
     Show Matching CPE(s)
Running on/with
 cpe:2.3:h:huawei:plk:-:*:*:*:*:*:*:*
     Show Matching CPE(s)

Configuration 4 ( hide )
AND
OR
 cpe:2.3:o:huawei:cherryplus_firmware:tl00c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:cherryplus_firmware:tl00mc01:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:huawei:cherryplus_firmware:ul00c00:*:*:*:*:*:*:*
     Show Matching CPE(s)
OR
 cpe:2.3:h:huawei:cherryplus:-:*:*:*:*:*:*:*
     Show Matching CPE(s)


Change History

3 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2016-4575
NVD Published Date:
05/25/2016
NVD Last Modified:
05/26/2016