CVE-2016-5231
HIGHHuawei Mate8 NXT-AL10C00B182 - Unauthenticated Permission Bypass and Data Deletion
Title source: llmDescription
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/91556
Vendor Advisory x_refsource_confirm
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160520-01-smartphone-en
Scores
CVSS v3
7.8
EPSS
0.0010
EPSS Percentile
26.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (1)
huawei/mate_8_firmware
nxt
Published
Jun 30, 2016
Tracked Since
Feb 18, 2026