First published: Wed Nov 22 2017(Updated: )
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <vtr-al00c00b167 | |
Huawei P10 | ||
Huawei P10 Plus Firmware | <vky-al00c00b167 | |
Huawei P10 Plus | ||
Huawei P10 Firmware | <vtr-tl00c01b167 | |
Huawei P10 Plus Firmware | <vky-tl00c01b167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8145 is a DoS vulnerability in the call module of Huawei P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, and VKY-TL00C01B167.
An attacker can trick a user into installing a malicious application, which can cause the call module of the affected Huawei smartphones to become unresponsive, leading to a denial of service (DoS) condition.
The severity of CVE-2017-8145 is rated as medium with a CVSSv2 score of 5.5.
The Huawei P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, and VKY-TL00C01B167 are affected by CVE-2017-8145.
To mitigate CVE-2017-8145, users should ensure that they only download and install applications from trusted sources and keep their smartphones updated with the latest software version.