HIGH · 7.8

CVE-2017-2699

The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could ...

Vulnerability Description

The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiHonor 7 Firmware< plk-ul00c17b385
HuaweiHonor 7-
HuaweiMate S Firmware< crr-l09c432b380
HuaweiMate S-
HuaweiLyo-L21 Firmware< lyo-l21c577b128
HuaweiLyo-L21-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-2699?

CVE-2017-2699 is a vulnerability with a CVSS score of 7.8 (HIGH). The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could ...

How severe is CVE-2017-2699?

CVE-2017-2699 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-2699?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Honor 7 Firmware, Huawei Honor 7, Huawei Mate S Firmware, Huawei Mate S, Huawei Lyo-L21 Firmware.