CVE-2017-2711

Severity
5.5MEDIUM
EPSS
0.1%
top 66.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 17

Description

P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone to crash the system.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p9_plus_firmware< vie-al10c00b352
CVEListV5huawei_technologies_co.,_ltd./p9_plusEarlier than VIE-AL10C00B352 versions

🔴Vulnerability Details

2
GHSA
GHSA-4639-4gpg-763x: P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver2022-05-17
CVEList
CVE-2017-2711: P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver2017-11-22
CVE-2017-2711 (MEDIUM CVSS 5.5) | P9 Plus smartphones with software e | cvebase.io