CVE-2017-17328

MEDIUM

Huawei MHA-AL00AC00B125 - Info Disclosure

Title source: llm
STIX 2.1

Description

Huawei smartphones with software of MHA-AL00AC00B125 have an integer overflow vulnerability. The software does not process certain variable properly when handle certain process. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could cause information disclosure.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-190
Status published
Products (1)
huawei/mha-al00a_firmware mha-al00ac00b125
Published Mar 09, 2018
Tracked Since Feb 18, 2026