CVE-2017-2694: Medium severity huawei vmall vulnerability
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2694?
CVE-2017-2694 has been rated as a low severity vulnerability due to the lack of sensitive data exposure.
How do I fix CVE-2017-2694?
To mitigate CVE-2017-2694, update the Huawei Vmall software to version 1.5.2.0 or later.
What impact does CVE-2017-2694 have on users?
CVE-2017-2694 can lead to unexpected alert sounds being played, compromising the user experience.
Which versions of Huawei Vmall are affected by CVE-2017-2694?
CVE-2017-2694 affects Huawei Vmall versions prior to 1.5.2.0.
Who can exploit CVE-2017-2694?
Any third-party application can exploit CVE-2017-2694 due to insufficient calling permissions in the AlarmService component.