Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8164


Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145; EVA-L09GBRC555B171; EVA-L09IRLC368B160; EVA-L19C10B190; EVA-L19C185B220; EVA-L19C20B160; EVA-L19C432B210; EVA-L19C636B190; EVA-L29C20B160; EVA-L29C636B191; EVA-TL00C01B198; VIE-L09C02B131; VIE-L09C109B181; VIE-L09C113B170; VIE-L09C150B170; VIE-L09C25B120; VIE-L09C40B181; VIE-L09C432B181; VIE-L09C55B170; VIE-L09C605B131; VIE-L09ITAC555B130; VIE-L29C10B170; VIE-L29C185B181; VIE-L29C605B131; VIE-L29C636B202 have a denial of service (DoS) vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation can cause camera application unusable.


Security Impact Summary

This vulnerability carries a LOW severity rating with a CVSS v3.1 score of 3.3, requiring local system access to exploit with relatively low complexity though user interaction is required and does not require pre-existing privileges . The vulnerability impacts and limited availability for affected systems. Impacting 18 products from huawei, from huawei, from huawei and 15 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2018, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2018-03-05T19:29:00.957

Last Modified

2024-11-21T03:33:26.990

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 3.3 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei eva-al10_firmware eva-al10c00b198 Yes
Hardware huawei eva-al10 - No
Operating System huawei eva-cl00_firmware eva-cl00c92b198 Yes
Hardware huawei eva-cl00 - No
Operating System huawei eva-dl00_firmware eva-dl00c17b198 Yes
Hardware huawei eva-dl00 - No
Operating System huawei eva-l09_firmware eva-l09c02b143 Yes
Operating System huawei eva-l09_firmware eva-l09c09b150 Yes
Operating System huawei eva-l09_firmware eva-l09c22b140 Yes
Operating System huawei eva-l09_firmware eva-l09c25b133 Yes
Operating System huawei eva-l09_firmware eva-l09c33b191 Yes
Operating System huawei eva-l09_firmware eva-l09c34b142 Yes
Operating System huawei eva-l09_firmware eva-l09c40b196 Yes
Operating System huawei eva-l09_firmware eva-l09c55b190 Yes
Operating System huawei eva-l09_firmware eva-l09c109b196 Yes
Operating System huawei eva-l09_firmware eva-l09c113b150 Yes
Operating System huawei eva-l09_firmware eva-l09c150b192 Yes
Operating System huawei eva-l09_firmware eva-l09c178b161 Yes
Operating System huawei eva-l09_firmware eva-l09c185b180 Yes
Operating System huawei eva-l09_firmware eva-l09c432b210 Yes
Operating System huawei eva-l09_firmware eva-l09c440b138 Yes
Operating System huawei eva-l09_firmware eva-l09c464b150 Yes
Operating System huawei eva-l09_firmware eva-l09c530b127 Yes
Operating System huawei eva-l09_firmware eva-l09c576b150 Yes
Operating System huawei eva-l09_firmware eva-l09c635b221 Yes
Operating System huawei eva-l09_firmware eva-l09c636b193 Yes
Operating System huawei eva-l09_firmware eva-l09c675b130 Yes
Operating System huawei eva-l09_firmware eva-l09c688b143 Yes
Operating System huawei eva-l09_firmware eva-l09c703b160 Yes
Operating System huawei eva-l09_firmware eva-l09c706b145 Yes
Operating System huawei eva-l09_firmware eva-l09gbrc555b171 Yes
Operating System huawei eva-l09_firmware eva-l09irlc368b160 Yes
Hardware huawei eva-l09 - No
Operating System huawei eva-l19_firmware eva-l19c10b190 Yes
Operating System huawei eva-l19_firmware eva-l19c20b160 Yes
Operating System huawei eva-l19_firmware eva-l19c185b220 Yes
Operating System huawei eva-l19_firmware eva-l19c432b210 Yes
Operating System huawei eva-l19_firmware eva-l19c636b190 Yes
Hardware huawei eva-l19 - No
Operating System huawei eva-l29_firmware eva-l29c20b160 Yes
Operating System huawei eva-l29_firmware eva-l29c636b191 Yes
Hardware huawei eva-l29 - No
Operating System huawei eva-tl00_firmware eva-tl00c01b198 Yes
Hardware huawei eva-tl00 - No
Operating System huawei vie-l09_firmware vie-l09c02b131 Yes
Operating System huawei vie-l09_firmware vie-l09c25b120 Yes
Operating System huawei vie-l09_firmware vie-l09c40b181 Yes
Operating System huawei vie-l09_firmware vie-l09c55b170 Yes
Operating System huawei vie-l09_firmware vie-l09c109b181 Yes
Operating System huawei vie-l09_firmware vie-l09c113b170 Yes
Operating System huawei vie-l09_firmware vie-l09c150b170 Yes
Operating System huawei vie-l09_firmware vie-l09c432b181 Yes
Operating System huawei vie-l09_firmware vie-l09c605b131 Yes
Operating System huawei vie-l09_firmware vie-l09itac555b130 Yes
Hardware huawei vie-l09 - No
Operating System huawei vie-l29_firmware vie-l29c10b170 Yes
Operating System huawei vie-l29_firmware vie-l29c185b181 Yes
Operating System huawei vie-l29_firmware vie-l29c605b131 Yes
Operating System huawei vie-l29_firmware vie-l29c636b202 Yes
Hardware huawei vie-l29 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For huawei's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.