CVE-2017-2727
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2017
Last modified:
20/04/2025
Description
Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privilege escalation vulnerability. An unauthenticated attacker can bypass phone activation to user management page of the phone and create a new user. Successful exploit could allow the attacker operate part function of the phone.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | eva-al00c00b365 (excluding) | |
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | eva-al10c00b365 (excluding) | |
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | eva-cl00c92b365 (excluding) | |
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | eva-dl00c17b365 (excluding) | |
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* | eva-tl00c01b365 (excluding) | |
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page