First published: Wed Nov 22 2017(Updated: )
Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <vtr-al00c00b123 | |
Huawei P10 | ||
Huawei P10 Plus Firmware | <vky-al00c00b123 | |
Huawei P10 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2726 is a vulnerability that affects Huawei P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions.
CVE-2017-2726 has a severity score of 8.4 out of 10, making it critical.
CVE-2017-2726 is a buffer overflow vulnerability that can be exploited by an attacker with root privilege to trick a user into installing a malicious APP.
Huawei P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions are vulnerable to CVE-2017-2726.
To mitigate CVE-2017-2726, ensure that you have the latest software version VKY-AL00C00B123 for Huawei P10 Plus or VTR-AL00C00B123 for Huawei P10 installed on your device.