Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-17159


Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.


Published

2018-02-15T16:29:01.970

Last Modified

2024-11-21T03:17:36.523

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei mt8-emui4.1_firmware nxt-al10c00b386 Yes
Operating System huawei mt8-emui4.1_firmware nxt-cl00c92b386 Yes
Operating System huawei mt8-emui4.1_firmware nxt-dl00c17b386 Yes
Operating System huawei mt8-emui4.1_firmware nxt-tl00c01b386sp01 Yes
Hardware huawei mt8-emui4.1 - No
Operating System huawei nts-al00_firmware nts-al00c00b535 Yes
Hardware huawei nts-al00 - No

References