CVE-2017-2731: Input Validation
The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vibrator service interface to crash the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2731?
CVE-2017-2731 is a DoS vulnerability in the vibrator service of Huawei P9 Plus smart phones with software versions earlier than VIE-AL10C00B386.
How does CVE-2017-2731 affect Huawei P9 Plus smart phones?
CVE-2017-2731 allows an attacker to crash the system of Huawei P9 Plus smart phones by sending a specific parameter to the vibrator service interface.
What is the severity of CVE-2017-2731?
CVE-2017-2731 has a severity rating of 5.5 (high).
How can I fix CVE-2017-2731 on my Huawei P9 Plus smart phone?
To fix CVE-2017-2731, update your Huawei P9 Plus smart phone software to version VIE-AL10C00B386 or later.
Where can I find more information about CVE-2017-2731?
You can find more information about CVE-2017-2731 on the Huawei PSIRT security advisories page at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170315-01-smartphone-en.