CVE-2017-8150

The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an arbitrary memory write vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause arbitrary memory writing in the next system reboot, causing continuous system reboot or arbitrary code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p10:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p10:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p10_plus:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p9:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-22 19:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-8150

Mitre link : CVE-2017-8150

CVE.ORG link : CVE-2017-8150


JSON object : View

Products Affected

huawei

  • p8_lite_firmware
  • p10_firmware
  • p9_firmware
  • p10_plus_firmware
  • p10
  • p10_plus
  • p9
  • p8_lite
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer