Vulnerability Description
Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mt8-Emui4.1 Firmware | nxt-al10c00b386 |
| Huawei | Mt8-Emui4.1 | - |
| Huawei | Nts-Al00 Firmware | nts-al00c00b535 |
| Huawei | Nts-Al00 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-02-smartphVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-02-smartphVendor Advisory
FAQ
What is CVE-2017-17159?
CVE-2017-17159 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unau...
How severe is CVE-2017-17159?
CVE-2017-17159 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17159?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mt8-Emui4.1 Firmware, Huawei Mt8-Emui4.1, Huawei Nts-Al00 Firmware, Huawei Nts-Al00.