CVE-2017-2735

TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:y6_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:y6_pro:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:24

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170329-01-smartphone-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170329-01-smartphone-en - Vendor Advisory
References () http://www.securityfocus.com/bid/97224 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/97224 - Third Party Advisory, VDB Entry

Information

Published : 2017-11-22 19:29

Updated : 2024-11-21 03:24


NVD link : CVE-2017-2735

Mitre link : CVE-2017-2735

CVE.ORG link : CVE-2017-2735


JSON object : View

Products Affected

huawei

  • y6_pro_firmware
  • y6_pro
CWE
CWE-749

Exposed Dangerous Method or Function