CVE-2017-8186

MEDIUM

Huawei MHA-AL00A < MHA-AL00BC00B231 - Denial of Service via Malicious APP Parameter Modification

Title source: llm
STIX 2.1

Description

The Bastet of some Huawei mobile phones with software of earlier than MHA-AL00BC00B231 versions has a DOS vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The APP can modify specific parameter to cause system reboot.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (2)
huawei/mha-al00a < mha-al00bc00b231
Huawei Technologies Co., Ltd./MHA-AL00A Earlier than MHA-AL00BC00B231 versions
Published Nov 22, 2017
Tracked Since Feb 18, 2026