CVE-2017-2694

LOW

HwVmall <1.5.2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95915

Scores

CVSS v3 3.3
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-275
Status published
Products (2)
huawei/vmall < 1.5.2.0
Huawei Technologies Co., Ltd./HwVmall Earlier than HwVmall 1.5.2.0 versions
Published Nov 22, 2017
Tracked Since Feb 18, 2026