CVE-2017-8146: Input Validation
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2017-8146.
What is the severity of CVE-2017-8146?
The severity of CVE-2017-8146 is medium with a CVSS score of 5.5.
What is the affected software?
The affected software includes P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, and VKY-TL00C01B167.
How can an attacker exploit CVE-2017-8146?
An attacker can exploit CVE-2017-8146 by tricking a user into installing a malicious application.
Is there a fix available for CVE-2017-8146?
Yes, it is recommended to update the software to versions VTR-AL00C00B167, VTR-TL00C01B167, VKY-AL00C00B167, or VKY-TL00C01B167 to fix CVE-2017-8146.