CVE-2016-3677

MEDIUM

Huawei Wear App <15.0.0.307 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/86536

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-254 CWE-345
Status published
Products (2)
huawei/hilink_app
huawei/wear_app
Published Jun 13, 2016
Tracked Since Feb 18, 2026