CVE-2017-8145: Input Validation
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-8145?
CVE-2017-8145 is a DoS vulnerability in the call module of Huawei P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, and VKY-TL00C01B167.
How does CVE-2017-8145 work?
An attacker can trick a user into installing a malicious application, which can cause the call module of the affected Huawei smartphones to become unresponsive, leading to a denial of service (DoS) condition.
What is the severity of CVE-2017-8145?
The severity of CVE-2017-8145 is rated as medium with a CVSSv2 score of 5.5.
Which Huawei smartphones are affected by CVE-2017-8145?
The Huawei P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, and VKY-TL00C01B167 are affected by CVE-2017-8145.
How can I mitigate the vulnerability in CVE-2017-8145?
To mitigate CVE-2017-8145, users should ensure that they only download and install applications from trusted sources and keep their smartphones updated with the latest software version.