CVE-2017-8164

LOW

Huawei EVA and VIE Firmware - Denial of Service via Malicious Application Installation

Title source: llm
STIX 2.1

Description

Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145; EVA-L09GBRC555B171; EVA-L09IRLC368B160; EVA-L19C10B190; EVA-L19C185B220; EVA-L19C20B160; EVA-L19C432B210; EVA-L19C636B190; EVA-L29C20B160; EVA-L29C636B191; EVA-TL00C01B198; VIE-L09C02B131; VIE-L09C109B181; VIE-L09C113B170; VIE-L09C150B170; VIE-L09C25B120; VIE-L09C40B181; VIE-L09C432B181; VIE-L09C55B170; VIE-L09C605B131; VIE-L09ITAC555B130; VIE-L29C10B170; VIE-L29C185B181; VIE-L29C605B131; VIE-L29C636B202 have a denial of service (DoS) vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation can cause camera application unusable.

References (1)

Core 1

Scores

CVSS v3 3.3
EPSS 0.0008
EPSS Percentile 24.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-20
Status published
Products (50)
huawei/eva-al10_firmware eva-al10c00b198
huawei/eva-cl00_firmware eva-cl00c92b198
huawei/eva-dl00_firmware eva-dl00c17b198
huawei/eva-l09_firmware eva-l09c02b143
huawei/eva-l09_firmware eva-l09c09b150
huawei/eva-l09_firmware eva-l09c22b140
huawei/eva-l09_firmware eva-l09c25b133
huawei/eva-l09_firmware eva-l09c33b191
huawei/eva-l09_firmware eva-l09c34b142
huawei/eva-l09_firmware eva-l09c40b196
... and 40 more
Published Mar 05, 2018
Tracked Since Feb 18, 2026