National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2017-8150 Detail

Current Description

The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause arbitrary memory writing in the next system reboot, causing continuous system reboot or arbitrary code execution.

Source:  MITRE
View Analysis Description

Impact

CVSS v3.0 Severity and Metrics:

Base Score: 7.8 HIGH
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (V3 legend)
Impact Score: 5.9
Exploitability Score: 1.8


Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): High
Availability (A): High

CVSS v2.0 Severity and Metrics:

Base Score: 9.3 HIGH
Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C) (V2 legend)
Impact Subscore: 10.0
Exploitability Subscore: 8.6


Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (AU): None
Confidentiality (C): Complete
Integrity (I): Complete
Availability (A): Complete
Additional Information:
Victim must voluntarily interact with attack mechanism
Allows unauthorized disclosure of information
Allows unauthorized modification
Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-02-smartphone-en Issue Tracking Vendor Advisory

Technical Details

Vulnerability Type (View All)

Known Affected Software Configurations Switch to CPE 2.3

Configuration 1 ( hide )
 cpe:/o:huawei:p10_firmware
     Show Matching CPE(s)
Up to (excluding)
victoria-l09ac605b162
Running on/with
 cpe:/h:huawei:p10:-
     Show Matching CPE(s)

Configuration 2 ( hide )
 cpe:/o:huawei:p10_firmware
     Show Matching CPE(s)
Up to (excluding)
victoria-l29ac605b162
Running on/with
 cpe:/h:huawei:p10:-
     Show Matching CPE(s)

Configuration 3 ( hide )
 cpe:/o:huawei:p10_plus_firmware
     Show Matching CPE(s)
Up to (excluding)
vicky-l29ac605b162
Running on/with
 cpe:/h:huawei:p10_plus:-
     Show Matching CPE(s)

Configuration 4 ( hide )
 cpe:/o:huawei:p8_lite_firmware
     Show Matching CPE(s)
Up to (excluding)
ale-l21c113b566
Running on/with
 cpe:/h:huawei:p8_lite:-
     Show Matching CPE(s)

Configuration 5 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l09c432b391
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 6 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l09c576b386
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 7 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l09c605b390
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 8 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l09c635b387
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 9 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l09c636b388
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 10 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l19c10b390
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 11 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l19c432b388
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 12 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l19c605b390
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)

Configuration 13 ( hide )
 cpe:/o:huawei:p9_firmware
     Show Matching CPE(s)
Up to (excluding)
eva-l19c636b391
Running on/with
 cpe:/h:huawei:p9:-
     Show Matching CPE(s)


Change History

1 change record found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2017-8150
NVD Published Date:
11/22/2017
NVD Last Modified:
12/08/2017