First published: Wed Nov 22 2017(Updated: )
The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vibrator service interface to crash the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P9 Plus Firmware | <vie-al10c00b386 | |
Huawei P9 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2731 is a DoS vulnerability in the vibrator service of Huawei P9 Plus smart phones with software versions earlier than VIE-AL10C00B386.
CVE-2017-2731 allows an attacker to crash the system of Huawei P9 Plus smart phones by sending a specific parameter to the vibrator service interface.
CVE-2017-2731 has a severity rating of 5.5 (high).
To fix CVE-2017-2731, update your Huawei P9 Plus smart phone software to version VIE-AL10C00B386 or later.
You can find more information about CVE-2017-2731 on the Huawei PSIRT security advisories page at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170315-01-smartphone-en.