CVE-2017-8177

Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file. An attacker could exploit this vulnerability to hijack the APK and upload modified APK file. Successful exploit could lead to the APP is hijacking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:huawei:hiwallet:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:33

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-01-app-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170816-01-app-en - Vendor Advisory

Information

Published : 2017-11-22 19:29

Updated : 2024-11-21 03:33


NVD link : CVE-2017-8177

Mitre link : CVE-2017-8177

CVE.ORG link : CVE-2017-8177


JSON object : View

Products Affected

huawei

  • hiwallet
CWE
CWE-347

Improper Verification of Cryptographic Signature