MEDIUM · 6.5

CVE-2017-17159

Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unau...

Vulnerability Description

Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiMt8-Emui4.1 Firmwarenxt-al10c00b386
HuaweiMt8-Emui4.1-
HuaweiNts-Al00 Firmwarents-al00c00b535
HuaweiNts-Al00-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-17159?

CVE-2017-17159 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unau...

How severe is CVE-2017-17159?

CVE-2017-17159 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-17159?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mt8-Emui4.1 Firmware, Huawei Mt8-Emui4.1, Huawei Nts-Al00 Firmware, Huawei Nts-Al00.