CVE-2017-2707: High severity huawei mate 9 firmware vulnerability
Published Nov 22, 2017
·Updated
Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message.
Affected Software
2 affected components
huawei Mate 9 Firmware<=mha-al00ac00b125
huawei Mate 9
Event History
Nov 22, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2017-2707.
2
What is the severity of CVE-2017-2707?
The severity of CVE-2017-2707 is high with a CVSS score of 7.1.
3
Which smartphones are affected by CVE-2017-2707?
Mate 9 smartphones with software MHA-AL00AC00B125 are affected by CVE-2017-2707.
4
How can an attacker exploit CVE-2017-2707?
An attacker can exploit CVE-2017-2707 by tricking a user to save a rich media into a message on the smartphone.
5
What is the recommended mitigation for CVE-2017-2707?
To mitigate CVE-2017-2707, users should update the software to a version that is not vulnerable.