// For flags

CVE-2017-2697

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The goldeneye driver in NMO-L31C432B120 and earlier versions,NEM-L21C432B100 and earlier versions,NEM-L51C432B120 and earlier versions,KNT-AL10C746B160 and earlier versions,VNS-L21C185B142 and earlier versions,CAM-L21C10B130 and earlier versions,CAM-L21C185B141 and earlier versions has buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone to crash the system or escalate privilege.

El controlador goldeneye en NMO-L31C432B120 y versiones anteriores; NEM-L21C432B100 y anteriores; NEM-L51C432B120 y anteriores; KNT-AL10C746B160 y anteriores; VNS-L21C185B142 y anteriores; CAM-L21C10B130 y anteriores y CAM-L21C185B141 y versiones anteriores tiene una vulnerabilidad de desbordamiento de búfer. Un atacante con el privilegio root del sistema Android puede engañar a un usuario para que instale una aplicación maliciosa en el smartphone y enviar parámetros al smartphone para que el sistema se cierre inesperadamente o se escalen privilegios.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2017-11-22 CVE Published
  • 2024-08-04 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
Gt3 Firmware
Search vendor "Huawei" for product "Gt3 Firmware"
<= nmo-l31c432b120
Search vendor "Huawei" for product "Gt3 Firmware" and version " <= nmo-l31c432b120"
-
Affected
in Huawei
Search vendor "Huawei"
Gt3
Search vendor "Huawei" for product "Gt3"
--
Safe
Huawei
Search vendor "Huawei"
Honor 5c Firmware
Search vendor "Huawei" for product "Honor 5c Firmware"
<= nem-l51c432b120
Search vendor "Huawei" for product "Honor 5c Firmware" and version " <= nem-l51c432b120"
-
Affected
in Huawei
Search vendor "Huawei"
Honor 5c
Search vendor "Huawei" for product "Honor 5c"
--
Safe
Huawei
Search vendor "Huawei"
Knt Firmware
Search vendor "Huawei" for product "Knt Firmware"
<= knt-al10c746b160
Search vendor "Huawei" for product "Knt Firmware" and version " <= knt-al10c746b160"
-
Affected
in Huawei
Search vendor "Huawei"
Knt
Search vendor "Huawei" for product "Knt"
--
Safe
Huawei
Search vendor "Huawei"
P9 Lite Firmware
Search vendor "Huawei" for product "P9 Lite Firmware"
<= vns-l21c185b142
Search vendor "Huawei" for product "P9 Lite Firmware" and version " <= vns-l21c185b142"
-
Affected
in Huawei
Search vendor "Huawei"
P9 Lite
Search vendor "Huawei" for product "P9 Lite"
--
Safe
Huawei
Search vendor "Huawei"
Y6ii Firmware
Search vendor "Huawei" for product "Y6ii Firmware"
<= cam-l21c10b130
Search vendor "Huawei" for product "Y6ii Firmware" and version " <= cam-l21c10b130"
-
Affected
in Huawei
Search vendor "Huawei"
Y6ii
Search vendor "Huawei" for product "Y6ii"
--
Safe
Huawei
Search vendor "Huawei"
Honor 5c Firmware
Search vendor "Huawei" for product "Honor 5c Firmware"
<= nem-l51c432b120
Search vendor "Huawei" for product "Honor 5c Firmware" and version " <= nem-l51c432b120"
-
Affected
in Huawei
Search vendor "Huawei"
Honor 5c
Search vendor "Huawei" for product "Honor 5c"
--
Safe
Huawei
Search vendor "Huawei"
Y6ii Firmware
Search vendor "Huawei" for product "Y6ii Firmware"
<= cam-l21c185b141
Search vendor "Huawei" for product "Y6ii Firmware" and version " <= cam-l21c185b141"
-
Affected
in Huawei
Search vendor "Huawei"
Y6ii
Search vendor "Huawei" for product "Y6ii"
--
Safe