« Volver al listado

CVE-2017-17306

Estado: ModificadaMedia (5.5)—

Some Huawei Smartphones with software of VNS-L21AUTC555B141, VNS-L21C10B160, VNS-L21C66B160, VNS-L21C703B140 have an array out-of-bounds read vulnerability. Due to the lack verification of array, an attacker tricks a user into installing a malicious application, and the application can exploit the vulnerability and make attacker to read out of bounds of array and possibly cause the device abnormal.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-17306",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei Technologies Co., Ltd.",
          "product": "VNS-L21",
          "versions": [
            {
              "status": "affected",
              "version": "VNS-L21AUTC555B141, VNS-L21C10B160, VNS-L21C66B160, VNS-L21C703B140"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-20T15:29:00.267",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180314-01-arrayover-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180314-01-arrayover-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Some Huawei Smartphones with software of VNS-L21AUTC555B141, VNS-L21C10B160, VNS-L21C66B160, VNS-L21C703B140 have an array out-of-bounds read vulnerability. Due to the lack verification of array, an attacker tricks a user into installing a malicious application, and the application can exploit the vulnerability and make attacker to read out of bounds of array and possibly cause the device abnormal."
    },
    {
      "lang": "es",
      "value": "Algunos smartphones Huawei con software VNS-L21AUTC555B141, VNS-L21C10B160, VNS-L21C66B160 o VNS-L21C703B140 tienen una vulnerabilidad de lectura de array fuera de límites. Debido a la falta de verificación del array, un atacante engaña a un usuario para que instale una aplicación maliciosa que pueda explotar la vulnerabilidad y hacer que el atacante lea fuera de los límites del array y que pueda hacer que el dispositivo funcione de forma errónea."
    }
  ],
  "lastModified": "2026-06-17T01:10:40.033",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:vns-l21_firmware:vns-l21autc555b141:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "599B0730-82A5-4DC9-A830-817ED14FACCF"
            },
            {
              "criteria": "cpe:2.3:o:huawei:vns-l21_firmware:vns-l21c10b160:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCDF5D9E-E608-4A46-82F3-4E5D8E0D5288"
            },
            {
              "criteria": "cpe:2.3:o:huawei:vns-l21_firmware:vns-l21c66b160:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78C6E201-2634-4269-84CF-18E8DD402F6A"
            },
            {
              "criteria": "cpe:2.3:o:huawei:vns-l21_firmware:vns-l21c703b140:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D677E2E5-C167-41AD-BEC1-D20ED5A5FBF2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:vns-l21:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F58ED157-A56B-4779-9731-7B7D859ACE02"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}