Show plain JSON{"id": "CVE-2017-8153", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.1, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 1.8}]}, "published": "2017-11-22T19:29:03.477", "references": [{"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170901-01-smartphone-en", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "psirt@huawei.com"}, {"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170901-01-smartphone-en", "tags": ["Issue Tracking", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-275"}]}], "descriptions": [{"lang": "en", "value": "Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. Successful exploit could lead to resource occupation or information leak."}, {"lang": "es", "value": "Huaweii VMall para Android en versiones anteriores a la 1.5.8.5 tiene una vulnerabilidad de elevaci\u00f3n de privilegios debido a un dise\u00f1o incorrecto. Un atacante podr\u00eda enga\u00f1ar a los usuarios para que instale una app maliciosa que env\u00ede peticiones HTTP y ejecute c\u00f3digo JavaScript en p\u00e1ginas web sin obtener el permiso de acceso a internet. Un exploit exitoso podr\u00eda provocar la ocupaci\u00f3n de recursos o fugas de informaci\u00f3n."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:huawei:vmall:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "B106CD65-7676-4F56-B1CD-55EB8A6A9A0A", "versionEndExcluding": "1.5.8.5"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@huawei.com"}