CVE-2017-2734

Severity
5.5MEDIUM
EPSS
0.1%
top 78.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 17

Description

P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a large number of memory allocation and the smart phone will be crash for memory exhaustion.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p9_plus_firmware< vie-al10bc00b386
CVEListV5huawei_technologies_co.,_ltd./p9_plusVersions earlier before VIE-AL10BC00B386

🔴Vulnerability Details

2
GHSA
GHSA-vcxx-jfx3-h7xh: P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability2022-05-17
CVEList
CVE-2017-2734: P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability2017-11-22
CVE-2017-2734 (MEDIUM CVSS 5.5) | P9 Plus smartphones with software v | cvebase.io