First published: Wed Nov 22 2017(Updated: )
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a out-of-bounds array access that results in smart phone restart.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Plus Firmware | <vky-al00c00b157 | |
Huawei P10 Plus | ||
Huawei P10 Firmware | <vtr-al00c00b157 | |
Huawei P10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2017-8172.
The title of this vulnerability is Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions.
The severity of CVE-2017-8172 is high with a CVSS score of 5.5.
An attacker can exploit this vulnerability by tricking a user into installing a malicious application on the smartphone.
The affected software includes Huawei P10 Plus firmware versions earlier than VKY-AL00C00B157 and Huawei P10 firmware versions earlier than VTR-AL00C00B157.