CVE-2017-17313
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
19/04/2018
Last modified:
22/05/2018
Description
The inputhub driver of HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS-L21C22B380, Versions earlier than VNS-L31C02B341, Versions earlier than VNS-L31C440B390, Versions earlier than VNS-L31C636B396 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP and the APP may sends specific data to the inputhub driver to exploit this vulnerability, successful exploit could cause the system reboot.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | vns-l31c02b341 (excluding) | |
| cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | vns-l21c22b380 (excluding) | |
| cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | vns-l31c02b341 (excluding) | |
| cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | vns-l31c440b390 (excluding) | |
| cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | vns-l31c636b396 (excluding) | |
| cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



