First published: Wed Nov 22 2017(Updated: )
Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <vtr-al00c00b123 | |
Huawei P10 | ||
Huawei P10 Plus Firmware | <vky-al00c00b123 | |
Huawei P10 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2724 is a buffer overflow vulnerability found in Huawei P10 Plus and P10 smartphones with software earlier than VKY-AL00C00B123 and VTR-AL00C00B123 versions.
CVE-2017-2724 is rated as critical with a severity score of 8.4 (out of 10).
The affected software includes Huawei P10 Plus and P10 smartphones with software earlier than VKY-AL00C00B123 and VTR-AL00C00B123 versions.
An attacker with root privilege of an Android system can trick a user into installing a malicious app, which can then modify specific information or launch other attacks.
To fix CVE-2017-2724, users should update their Huawei P10 Plus and P10 smartphones to software versions VKY-AL00C00B123 and VTR-AL00C00B123 or later provided by Huawei.