CVE-2017-17319

Severity
5.5MEDIUM
EPSS
0.1%
top 72.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 14

Description

Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not properly protect certain resource which can be accessed by multithreading. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could result in kernel information disclosure.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p9_firmware< eva-al10c00b399sp02
CVEListV5huawei_technologies_co.,_ltd./p9The versions before EVA-AL10C00B399SP02

🔴Vulnerability Details

2
GHSA
GHSA-57p4-7ph9-v9qx: Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability2022-05-14
CVEList
CVE-2017-17319: Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability2018-03-20
CVE-2017-17319 (MEDIUM CVSS 5.5) | Huawei P9 smartphones with the vers | cvebase.io