Vulnerability Description
HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APPs installed access the Wi-Fi hotpot built by attacker, the attacker can collect the information of iPhone mode and firmware version.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Hilink | < 5.0.25.306 |
| Huawei | Tech Support | < 5.0.0 |
| Apple | Iphone Os | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170310-01-hilinkaVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170310-01-hilinkaVendor Advisory
FAQ
What is CVE-2017-2730?
CVE-2017-2730 is a vulnerability with a CVSS score of 3.5 (LOW). HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APP...
How severe is CVE-2017-2730?
CVE-2017-2730 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2730?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Hilink, Huawei Tech Support, Apple Iphone Os.