First published: Thu Feb 15 2018(Updated: )
Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth AVDTP/AVCTP messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Lon-al00b Firmware | <=lon-al00bc00b229 | |
Huawei Lon-al00b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17285 is categorized as high due to its potential for buffer overflow vulnerabilities in Bluetooth communication.
To fix CVE-2017-17285, users should update their Huawei devices to a version later than LON-AL00BC00B229.
CVE-2017-17285 affects certain Huawei mobile phones running the LON-AL00BC00B229 firmware or earlier.
Yes, the buffer overflow in CVE-2017-17285 can be exploited by an unauthenticated attacker after successful pairing via Bluetooth.
CVE-2017-17285 enables attackers to craft malicious Bluetooth AVDTP/AVCTP messages that can lead to unauthorized access or device malfunction.