// For flags

CVE-2017-2733

 

Severity Score

5.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Honor 6X smartphones with software versions earlier than BLN-AL10C00B357 and versions earlier than BLN-AL20C00B357 have an information leak vulnerability due to improper file permission configuration. An attacker tricks a user into installing a malicious application on the smart phone, and the application can get the file that keep the cipher text of the SIM card PIN.

Los smartphones Honor 6x con versiones de software anteriores a la BLN-AL10C00B357 y a la BLN-AL20C00B357 tienen una vulnerabilidad de filtrado de información debido a la configuración incorrecta de permisos de archivo. Un atacante engaña a un usuario para que instale una aplicación maliciosa en el smartphone; la aplicación puede conseguir el archivo que guarda el texto cifrado del PIN de la tarjeta SIM.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2017-11-22 CVE Published
  • 2023-05-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
Honor 6x Firmware
Search vendor "Huawei" for product "Honor 6x Firmware"
< bln-al10c00b357
Search vendor "Huawei" for product "Honor 6x Firmware" and version " < bln-al10c00b357"
-
Affected
in Huawei
Search vendor "Huawei"
Honor 6x
Search vendor "Huawei" for product "Honor 6x"
--
Safe
Huawei
Search vendor "Huawei"
Honor 6x Firmware
Search vendor "Huawei" for product "Honor 6x Firmware"
< bln-al20c00b357
Search vendor "Huawei" for product "Honor 6x Firmware" and version " < bln-al20c00b357"
-
Affected
in Huawei
Search vendor "Huawei"
Honor 6x
Search vendor "Huawei" for product "Honor 6x"
--
Safe