CVE-2017-17171: Input Validation
Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters. An attacker may trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions. Successful exploit could allow the app to send specific parameters to the smart phone driver, which will result in system restart.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-17171.
What is the severity of CVE-2017-17171?
The severity of CVE-2017-17171 is medium.
Which Huawei devices are affected by CVE-2017-17171?
Some Huawei smart phones, such as Huawei Mate 8 and Huawei P9, are affected by CVE-2017-17171.
How can an attacker exploit CVE-2017-17171?
An attacker can trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions.
Are there any fixes or patches available for CVE-2017-17171?
Yes, Huawei has released security advisories and patches to fix CVE-2017-17171. Please refer to the references for more information.