Vulnerability Description
Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth AVDTP/AVCTP messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Lon-Al00B Firmware | <= lon-al00bc00b229 |
| Huawei | Lon-Al00B | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180129-01-bluetooVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180129-01-bluetooVendor Advisory
FAQ
What is CVE-2017-17285?
CVE-2017-17285 is a vulnerability with a CVSS score of 8.8 (HIGH). Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker...
How severe is CVE-2017-17285?
CVE-2017-17285 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17285?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Lon-Al00B Firmware, Huawei Lon-Al00B.