CVE-2017-2735
Severity CVSS v4.0:
Pending analysis
Type:
CWE-749
Exposed Dangerous Method or Function
Publication date:
22/11/2017
Last modified:
20/04/2025
Description
TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:y6_pro_firmware:*:*:*:*:*:*:*:* | tit-al00c583b214 (excluding) | |
cpe:2.3:h:huawei:y6_pro:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page