CVE-2017-2727
4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.0%
top 91.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22
Latest updateMay 13
Description
Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privilege escalation vulnerability. An unauthenticated attacker can bypass phone activation to user management page of the phone and create a new user. Successful exploit could allow the attacker operate part function of the phone.
CVSS vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4
Affected Packages2 packages
▶CVEListV5huawei_technologies_co.,_ltd./huawei_p9Versions earlier before EVA-AL00C00B365,Versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365,Versions earlier before EVA-DL00C17B365,Versions earlier before EVA-TL00C01B365,,
🔴Vulnerability Details
2GHSA▶
GHSA-7w3q-qffv-c74h: Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00↗2022-05-13
CVEList▶
CVE-2017-2727: Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00↗2017-11-22
💬Community
1Bugzilla▶
CVE-2017-13726 libtiff: Reachable assertion abort in the function TIFFWriteDirectorySec()↗2017-09-06