CVE-2017-8154
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download. An attacker may exploit this vulnerability to tamper with downloaded themes.
Los teléfonos móviles Themes App Honor 8 Lite Huawei con versiones de software anteriores a Prague-L31C576B172, anteriores a Prague-L31C530B160 y anteriores a Prague-L31C432B180 tienen una vulnerabilidad Man-in-the-Middle (MitM) debido al uso del protocolo no seguro HTTP para la descarga de temas. Un atacante podría explotar esta vulnerabilidad para manipular temas descargados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-25 CVE Reserved
- 2018-04-11 CVE Published
- 2024-02-19 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170908-01-smartphone-en | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Honor 8 Lite Firmware Search vendor "Huawei" for product "Honor 8 Lite Firmware" | < prague-l31c530b160 Search vendor "Huawei" for product "Honor 8 Lite Firmware" and version " < prague-l31c530b160" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor 8 Lite Search vendor "Huawei" for product "Honor 8 Lite" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Honor 8 Lite Firmware Search vendor "Huawei" for product "Honor 8 Lite Firmware" | < prague-l31c576b172 Search vendor "Huawei" for product "Honor 8 Lite Firmware" and version " < prague-l31c576b172" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor 8 Lite Search vendor "Huawei" for product "Honor 8 Lite" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Honor 8 Lite Firmware Search vendor "Huawei" for product "Honor 8 Lite Firmware" | < prague-l31c432b180 Search vendor "Huawei" for product "Honor 8 Lite Firmware" and version " < prague-l31c432b180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor 8 Lite Search vendor "Huawei" for product "Honor 8 Lite" | - | - |
Safe
|