First published: Wed Nov 22 2017(Updated: )
Huawei smart phones with software earlier than VIE-L09C40B360 versions have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has the root privilege; the APP can send a specific parameter to the smart phone, causing the smartphone restart or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Vie-l09 Firmware | <vie-l09c40b360 | |
Huawei Vie-l09 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8169 is classified as a medium severity vulnerability that can be exploited through a buffer overflow.
To fix CVE-2017-8169, users should update their Huawei devices to the software version VIE-L09C40B360 or later.
CVE-2017-8169 affects Huawei smartphones running software versions earlier than VIE-L09C40B360.
CVE-2017-8169 enables attackers to exploit buffer overflow vulnerabilities via a malicious application with root privileges.
CVE-2017-8169 requires user interaction, as it involves tricking the user to install a malicious app.