cbcvebase.
CVE-2017-8172
published 2017-11-22

CVE-2017-8172: Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service…

medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a out-of-bounds array access that results in smart phone restart.

Affected

2 ranges
VendorProductVersion rangeFixed in
huaweip10_firmware< vtr-al00c00b157vtr-al00c00b157
huaweip10_plus_firmware< vky-al00c00b157vky-al00c00b157