cbcvebase.
CVE-2017-2713
published 2017-11-22

CVE-2017-2713: HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370…

PriorityP422medium5.4CVSS 3.0
AVAACLPRNUINSUCLILAN
EPSS
0.34%
26.1th percentile
HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability. An attacker could exploit this vulnerability to tamper with air interface signaling messages and obtain some communication information.

Affected

5 ranges
VendorProductVersion rangeFixed in
huaweip9_firmware< eva-l09c432b383eva-l09c432b383
huaweip9_firmware< eva-l09c636b380eva-l09c636b380
huaweip9_firmware< vie-l09c432b370vie-l09c432b370
huaweip9_firmware< vie-l29c636b370vie-l29c636b370
huawei_technologies_co_ltdhuawei_p9

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.