First published: Mon Mar 05 2018(Updated: )
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Enjoy 5s Firmware | <tag-al00c92b170 | |
Huawei Enjoy 5s | ||
Huawei Y6 Pro Firmware | <tit-l01c576b121 | |
Huawei Y6 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-17140.
Huawei Enjoy 5s and Y6 Pro smartphones with software versions before TAG-AL00C92B170 and TIT-L01C576B121 are affected.
The severity of CVE-2017-17140 is medium with a severity value of 5.5.
The information leak vulnerability is caused by the lack of parameter validation in the affected Huawei smartphones.
To fix the information leak vulnerability, update the software on the affected Huawei smartphones to versions TAG-AL00C92B170 and TIT-L01C576B121 or later.