RSS   Vulnerabilities for 'Mate 9 firmware'   RSS

2018-10-17
 
CVE-2017-17176

CWE-787
 

 
The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.

 
2017-11-22
 
CVE-2017-8144

CWE-920
 

 
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting. An attacker tricks a user into installing a malicious application, the application may turn on the device flash-light and rapidly drain the device battery.

 
 
CVE-2017-2707

CWE-494
 

 
Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message.

 
 
CVE-2017-2706

CWE-22
 

 
Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker to replace files and impact the service.

 
 
CVE-2017-2703

CWE-noinfo
 

 
Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00B373,Versions earlier before EVA-DL10C00B373,Versions earlier before EVA-TL10C00B373 can be bypass. An attacker can bypass the Phone Finder by special steps and enter the System Setting.

 
 
CVE-2017-2702

CWE-noinfo
 

 
Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone.

 
 
CVE-2017-2701

CWE-345
 

 
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.

 

 >>> Vendor: Huawei 665 Products
S8500
Versatile routing platform
D100
D100 router
Mt882 v100t002b020 arg-t
Mt882 modem firmware
Mt882 modem
E585
E585u-82
ACU
ATN
Cx200
Cx300
Cx600
Ma5200g
ME60
NE20
Ne20e-x6
NE40
Ne40e
Ne40e/80e
Ne5000e
NE80
Ne80e
S2300
S2700
S3300
S3300hi
S3700
S5300
S5300hi
S5306
S5700
S6300
S6700
S7700
S9300
Wlan ac 6605
Ar 19/29/49
Ar g3
E200 usg2200
E200 usg5100
E200e-b
E200e-c
E200e-usg2100
E200e-x1
E200e-x2
E200x3
E200x5
E200x7
Eudemon1000
Eudemon1000e-u
Eudemon1000e-x
Eudemon100e
Eudemon200
Eudemon300
Eudemon500
Eudemon8000e-x
Eudemon 8080e
Eudemon 8160e
Eudemon usg5300
Eudemon usg5500
Eudemon usg9300
Eudemon usg9500
H3c ar(oem in)
Nip100
Nip1000
Nip200
Nip2100
Nip2200
Nip5100
Svn2000
Svn3000
Svn5000
Svn5300
UTPS
Ar 18-1x
Ar 18-2x
Ar 18-3x
Ar 28/46
S2000
S3000
S3500
S3900
S5100
S5600
S7800
Quidway service process unit board s7700
Quidway service process unit board s9300
Quidway service process unit board s9700
Vp 9610
Vp 9620
Ar 1200
Ar 150
Ar 200
Ar 2200
Ar 3200
Access router
Seco versatile security manager
Mt882
See all Products for Vendor Huawei


Copyright 2024, cxsecurity.com

 

Back to Top