// For flags

CVE-2017-8216

 

Severity Score

5.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission control vulnerability. Due to improper authorization on specific processes, an attacker with the root privilege of a mobile Android system can exploit this vulnerability to obtain some information of the user.

Los smartphones Huawei Warsaw con versiones de software anteriores a Warsaw-AL00C00B180 y Warsaw-TL10C01B180 tienen una vulnerabilidad de control de permisos. Debido a la autorización incorrecta en procesos específicos, un atacante con el privilegio root de un sistema móvil Android puede explotar esta vulnerabilidad para obtener determinada información del usuario.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-04-25 CVE Reserved
  • 2017-11-22 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
P10 Lite Firmware
Search vendor "Huawei" for product "P10 Lite Firmware"
< warsaw-al00c00b180
Search vendor "Huawei" for product "P10 Lite Firmware" and version " < warsaw-al00c00b180"
android
Affected
in Huawei
Search vendor "Huawei"
P10 Lite
Search vendor "Huawei" for product "P10 Lite"
--
Safe
Huawei
Search vendor "Huawei"
P10 Lite Firmware
Search vendor "Huawei" for product "P10 Lite Firmware"
< warsaw-tl10c01b180
Search vendor "Huawei" for product "P10 Lite Firmware" and version " < warsaw-tl10c01b180"
android
Affected
in Huawei
Search vendor "Huawei"
P10 Lite
Search vendor "Huawei" for product "P10 Lite"
--
Safe