Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8154


The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.


Published

2018-04-11T17:29:00.257

Last Modified

2024-11-21T03:33:25.723

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

4.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei honor_8_lite_firmware < prague-l31c530b160 Yes
Hardware huawei honor_8_lite - No
Operating System huawei honor_8_lite_firmware < prague-l31c576b172 Yes
Hardware huawei honor_8_lite - No
Operating System huawei honor_8_lite_firmware < prague-l31c432b180 Yes
Hardware huawei honor_8_lite - No

References