Vulnerability Description
The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted package.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | P7-L10 Firmware | <= v100r001c00b135 |
| Huawei | P7-L10 | All versions |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99283
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99283
FAQ
What is CVE-2014-9135?
CVE-2014-9135 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted ...
How severe is CVE-2014-9135?
CVE-2014-9135 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9135?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei P7-L10 Firmware, Huawei P7-L10.