First published: Wed Nov 22 2017(Updated: )
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause arbitrary memory writing in the next system reboot, causing continuous system reboot or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <victoria-l09ac605b162 | |
Huawei P10 | ||
Huawei P10 Firmware | <victoria-l29ac605b162 | |
Huawei P10 Plus Firmware | <vicky-l29ac605b162 | |
Huawei P10 Plus | ||
Huawei P8 Lite Firmware | <ale-l21c113b566 | |
Huawei P8 Lite | ||
Huawei P9 Firmware | <eva-l09c432b391 | |
Huawei P9 | ||
Huawei P9 Firmware | <eva-l09c576b386 | |
Huawei P9 Firmware | <eva-l09c605b390 | |
Huawei P9 Firmware | <eva-l09c635b387 | |
Huawei P9 Firmware | <eva-l09c636b388 | |
Huawei P9 Firmware | <eva-l19c10b390 | |
Huawei P9 Firmware | <eva-l19c432b388 | |
Huawei P9 Firmware | <eva-l19c605b390 | |
Huawei P9 Firmware | <eva-l19c636b391 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8150 is a vulnerability in the boot loaders of P10 and P10 Plus Huawei mobile phones.
CVE-2017-8150 has a severity rating of 7.8, which is considered critical.
The boot loaders of P10 and P10 Plus Huawei mobile phones with software versions before Victoria-L09AC605B162, Victoria-L29AC605B162, and Vicky-L29AC605B162 are affected.
The vulnerability allows an attacker with arbitrary code execution permissions to modify memory, potentially leading to unauthorized access or control of the affected device.
To fix CVE-2017-8150, users should update their Huawei P10 or P10 Plus mobile phones to software versions Victoria-L09AC605B162, Victoria-L29AC605B162, or Vicky-L29AC605B162.