CVE-2017-8145
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
22/11/2017
Last modified:
20/04/2025
Description
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability. An attacker may trick a user into installing a malicious application, and the application can send given parameter to call module to crash the call and data communication process.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | vtr-al00c00b167 (excluding) | |
| cpe:2.3:h:huawei:p10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* | vky-al00c00b167 (excluding) | |
| cpe:2.3:h:huawei:p10_plus:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | vtr-tl00c01b167 (excluding) | |
| cpe:2.3:h:huawei:p10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* | vky-tl00c01b167 (excluding) | |
| cpe:2.3:h:huawei:p10_plus:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



