RSS   Vulnerabilities for 'Mate 9 pro firmware'   RSS

2018-11-27
 
CVE-2018-7988

CWE-863
 

 
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.

 
2018-10-17
 
CVE-2017-17176

CWE-787
 

 
The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.

 
2018-03-20
 
CVE-2017-17320

CWE-415
 

 
Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability. The system does not manage the memory properly, that frees on the same memory address twice. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could result in malicious code execution.

 
2018-03-09
 
CVE-2017-17324

CWE-190
 

 
Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer overflow vulnerability. The camera driver does not validate the external input parameters and causes an integer overflow, which in the after processing results in a buffer overflow. An attacker tricks the user to install a crafted application, successful exploit could cause malicious code execution.

 
 
CVE-2017-17279

CWE-noinfo
 

 
The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-AL00B 8.0.0.343(C00) has an authentication bypass vulnerability due to the improper design of the module. An attacker tricks a user into installing a malicious application, and the application can exploit the vulnerability and make attacker bypass the authentication, the attacker can control the phone to sent short messages and make call within audio range to the phone.

 
2018-02-15
 
CVE-2017-15347

CWE-416
 

 
Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can riggers access memory after free it. A local attacker may exploit this vulnerability to cause the mobile phone to crash.

 
2017-11-22
 
CVE-2017-8144

CWE-920
 

 
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting. An attacker tricks a user into installing a malicious application, the application may turn on the device flash-light and rapidly drain the device battery.

 

 >>> Vendor: Huawei 665 Products
S8500
Versatile routing platform
D100
D100 router
Mt882 v100t002b020 arg-t
Mt882 modem firmware
Mt882 modem
E585
E585u-82
ACU
ATN
Cx200
Cx300
Cx600
Ma5200g
ME60
NE20
Ne20e-x6
NE40
Ne40e
Ne40e/80e
Ne5000e
NE80
Ne80e
S2300
S2700
S3300
S3300hi
S3700
S5300
S5300hi
S5306
S5700
S6300
S6700
S7700
S9300
Wlan ac 6605
Ar 19/29/49
Ar g3
E200 usg2200
E200 usg5100
E200e-b
E200e-c
E200e-usg2100
E200e-x1
E200e-x2
E200x3
E200x5
E200x7
Eudemon1000
Eudemon1000e-u
Eudemon1000e-x
Eudemon100e
Eudemon200
Eudemon300
Eudemon500
Eudemon8000e-x
Eudemon 8080e
Eudemon 8160e
Eudemon usg5300
Eudemon usg5500
Eudemon usg9300
Eudemon usg9500
H3c ar(oem in)
Nip100
Nip1000
Nip200
Nip2100
Nip2200
Nip5100
Svn2000
Svn3000
Svn5000
Svn5300
UTPS
Ar 18-1x
Ar 18-2x
Ar 18-3x
Ar 28/46
S2000
S3000
S3500
S3900
S5100
S5600
S7800
Quidway service process unit board s7700
Quidway service process unit board s9300
Quidway service process unit board s9700
Vp 9610
Vp 9620
Ar 1200
Ar 150
Ar 200
Ar 2200
Ar 3200
Access router
Seco versatile security manager
Mt882
See all Products for Vendor Huawei


Copyright 2024, cxsecurity.com

 

Back to Top