CVE-2017-17158 - CVE House
Back to Database
Status published Medium CVE-2017-17158

Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the...

Vulnerability Description

Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-17158

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Huawei Technologies Co., Ltd.

View all reports →

Affected Software

Berlin-L21HN; Prague-AL00A; Prague-AL00B; Prague-AL00C; Prague-L31; Prague-TL00A; Prague-TL10A
Vulnerable Versions:
The versions before Berlin-L21HNC185B381, The versions before Prague-AL00AC00B223, The versions before Prague-AL00BC00B223, The versions before Prague-AL00CC00B223, The versions before Prague-L31C432B208, The versions before Prague-TL00AC01B223

Timeline

Official Publish: May 24th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.