CVE-2017-17326
https://notcve.org/view.php?id=CVE-2017-17326
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to bypass the activation lock and activate the smartphone by a new account after a series of operation. Los smartphones Huawei Mate 9 Pro con software LON-AL00BC00B139D y LON-AL00BC00B229 tienen una vulnerabilidad de omisión de bloqueo de activación. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171227-01-smartphone-en •
CVE-2017-17139
https://notcve.org/view.php?id=CVE-2017-17139
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date service proxy implementation. An attacker may trick a user into installing a malicious application and application can exploit the vulnerability to get kernel date which may cause sensitive information leak. Los smartphones Huawei Mate 9 y Mate 9 pro con software en versiones anteriores a la MHA-AL00B 8.0.0.334(C00) y a la LON-AL00B 8.0.0.334(C00) tienen una vulnerabilidad de filtrado de información en la implementación del proxy de servicio de fecha. Un atacante podría engañar a un usuario para que instale una aplicación maliciosa que pueda explotar la vulnerabilidad para obtener la fecha del kernel, lo que podría causar una filtración de información sensible. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171213-04-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-8165
https://notcve.org/view.php?id=CVE-2017-8165
Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation may cause sensitive information leak. Los smartphones Huawei Mate 9 con versiones anteriores a la MHA-AL00BC00B233 tienen una vulnerabilidad de filtrado de información sensible. Un atacante puede engañar a un usuario para que instale una aplicación maliciosa para explotar esta vulnerabilidad. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171117-01-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-15347
https://notcve.org/view.php?id=CVE-2017-15347
Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can riggers access memory after free it. A local attacker may exploit this vulnerability to cause the mobile phone to crash. Los teléfonos móviles Huawei Mate 9 Pro con versiones de software anteriores a LON-AL00BC00B235 tienen una vulnerabilidad de uso de memoria previamente liberada (UAF). Un atacante engaña a un usuario para que instale una aplicación maliciosa que desencadene un acceso a la memoria tras liberarla. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-phone-en • CWE-416: Use After Free •
CVE-2017-15311
https://notcve.org/view.php?id=CVE-2017-15311
The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker could exploit this vulnerability to perform a denial of service attack or remote code execution in baseband module. Los módulos baseband de los smartphones Huawei Mate 10, Mate 10 Pro, Mate 9 y Mate 9 Pro con versiones de software anteriores a ALP-AL00 8.0.0.120(SP2C00), anteriores a BLA-AL00 8.0.0.120(SP2C00), anteriores a MHA-AL00B 8.0.0.334(C00) y anteriores a LON-AL00B 8.0.0.334(C00) incluyen una vulnerabilidad de desbordamiento de pila debido a una falta de validación de parámetros. Un atacante podría enviar paquetes maliciosos a los smartphones dentro del rango de radio mediante dispositivos inalámbricos especiales. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171125-01-baseband-en • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •