CVE-2017-8170

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
22/11/2017
Last modified:
20/04/2025

Description

Huawei smart phones with software earlier than VIE-L09C40B360 versions have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has the root privilege; the APP can send a specific parameter to the smart phone, causing the smartphone restart or arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:vie-l09_firmware:*:*:*:*:*:*:*:* vie-l09c40b360 (excluding)
cpe:2.3:h:huawei:vie-l09:-:*:*:*:*:*:*:*