CVE-2017-2733
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerability due to improper file permission configuration. An attacker tricks a user into installing a malicious application on the smart phone, and the application can get the file that keep the cipher text of the SIM card PIN.
Los smartphones Honor 6x con versiones de software anteriores a la BLN-AL10C00B357 y a la BLN-AL20C00B357 tienen una vulnerabilidad de filtrado de información debido a la configuración incorrecta de permisos de archivo. Un atacante engaña a un usuario para que instale una aplicación maliciosa en el smartphone; la aplicación puede conseguir el archivo que guarda el texto cifrado del PIN de la tarjeta SIM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2017-11-22 CVE Published
- 2023-05-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97700 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170405-02-smartphone-en | 2017-12-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Honor 6x Firmware Search vendor "Huawei" for product "Honor 6x Firmware" | < bln-al10c00b357 Search vendor "Huawei" for product "Honor 6x Firmware" and version " < bln-al10c00b357" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor 6x Search vendor "Huawei" for product "Honor 6x" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Honor 6x Firmware Search vendor "Huawei" for product "Honor 6x Firmware" | < bln-al20c00b357 Search vendor "Huawei" for product "Honor 6x Firmware" and version " < bln-al20c00b357" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor 6x Search vendor "Huawei" for product "Honor 6x" | - | - |
Safe
|