CVE-2017-2727

4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.0%
top 91.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 13

Description

Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privilege escalation vulnerability. An unauthenticated attacker can bypass phone activation to user management page of the phone and create a new user. Successful exploit could allow the attacker operate part function of the phone.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4

Affected Packages2 packages

NVDhuawei/p9_firmware< eva-al00c00b365+4
CVEListV5huawei_technologies_co.,_ltd./huawei_p9Versions earlier before EVA-AL00C00B365,Versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365,Versions earlier before EVA-DL00C17B365,Versions earlier before EVA-TL00C01B365,,

🔴Vulnerability Details

2
GHSA
GHSA-7w3q-qffv-c74h: Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL002022-05-13
CVEList
CVE-2017-2727: Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL002017-11-22

💬Community

1
Bugzilla
CVE-2017-13726 libtiff: Reachable assertion abort in the function TIFFWriteDirectorySec()2017-09-06
CVE-2017-2727 (MEDIUM CVSS 4.3) | Huawei P9 smart phones with softwar | cvebase.io