First published: Wed Nov 22 2017(Updated: )
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting. An attacker tricks a user into installing a malicious application, the application may turn on the device flash-light and rapidly drain the device battery.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 5a Firmware | <cam-l03c605b143custc605d003 | |
Huawei Honor 5a | ||
Huawei Honor 8 Lite Firmware | <prague-l03c605b161 | |
Huawei Honor 8 Lite | ||
Huawei Honor 8 Lite Firmware | <prague-l23c605b160 | |
Huawei Mate 9 Firmware | <mha-al00c00b225 | |
Huawei Mate 9 | ||
Huawei Mate 9 Pro Firmware | <lon-al00c00b225 | |
Huawei Mate 9 Pro | ||
Huawei P10 Firmware | <vtr-al00c00b167 | |
Huawei P10 | ||
Huawei P10 Firmware | <vtr-tl00c01b167 | |
Huawei P10 Plus Firmware | <vky-al00c00b167 | |
Huawei P10 Plus | ||
Huawei P10 Plus Firmware | <vky-tl00c01b167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8144 is high with a value of 5.5.
Honor 5A, Honor 8 Lite, Mate9, Mate9 Pro, P10, and P10 Plus Huawei smartphones are affected by CVE-2017-8144.
The vulnerable software version for Huawei Honor 5A is CAM-L03C605B143CUSTC605D003.
The vulnerable software version for Huawei Honor 8 Lite is Prague-L03C605B161.
You can find more information about CVE-2017-8144 on the Huawei website: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170725-01-smartphone-en