CVE-2017-2731Improper Input Validation in Huawei P9 Plus Firmware

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 78.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 17

Description

The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vibrator service interface to crash the system.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p9_plus_firmware< vie-al10c00b386
CVEListV5huawei_technologies_co_ltd/p9_plusVersions earlier before VIE-AL10C00B386

🔴Vulnerability Details

2
GHSA
GHSA-q33q-57p3-8gx8: The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability2022-05-17
CVEList
CVE-2017-2731: The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability2017-11-22
CVE-2017-2731 — Improper Input Validation in Huawei | cvebase