CVE-2017-8172
published 2017-11-22CVE-2017-8172: Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service…
medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a out-of-bounds array access that results in smart phone restart.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | p10_firmware | < vtr-al00c00b157 | vtr-al00c00b157 |
| huawei | p10_plus_firmware | < vky-al00c00b157 | vky-al00c00b157 |