Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-2699


The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.


Published

2017-11-22T19:29:00.567

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei honor_7_firmware < plk-ul00c17b385 Yes
Hardware huawei honor_7 - No
Operating System huawei mate_s_firmware < crr-l09c432b380 Yes
Hardware huawei mate_s - No
Operating System huawei lyo-l21_firmware < lyo-l21c577b128 Yes
Hardware huawei lyo-l21 - No

References