« Volver al listado

CVE-2016-8775

Estado: ModificadaMedia (6.7)—

El controlador Touch Panel (TP) en teléfonos Huawei NEM con versiones de software anteriores a NEM-AL10C00B130, versiones anteriores a NEM-UL10C17B160, versiones anteriores a NEM-UL10C00B160, versiones anteriores a NEM-TL00C01B160 permiten a atacantes obtener privilegios de root o bloquear el sistema o ejecutar código arbitrario, relacionado con un desbordamiento de búfer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8775",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "NEM Versions before NEM-AL10C00B130,Versions before NEM-UL10C17B160,Versions before NEM-UL10C00B160,Versions before NEM-TL00C01B160,",
          "versions": [
            {
              "status": "affected",
              "version": "NEM Versions before NEM-AL10C00B130,Versions before NEM-UL10C17B160,Versions before NEM-UL10C00B160,Versions before NEM-TL00C01B160,"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-02T20:59:01.470",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161123-03-smartphone-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/94506",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161123-03-smartphone-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/94506",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Touch Panel (TP) driver in Huawei NEM phones with software Versions before NEM-AL10C00B130, Versions before NEM-UL10C17B160, Versions before NEM-UL10C00B160, Versions before NEM-TL00C01B160 allows attackers to get root privilege or crash the system or execute arbitrary code, related to a buffer overflow."
    },
    {
      "lang": "es",
      "value": "El controlador Touch Panel (TP) en teléfonos Huawei NEM con versiones de software anteriores a NEM-AL10C00B130, versiones anteriores a NEM-UL10C17B160, versiones anteriores a NEM-UL10C00B160, versiones anteriores a NEM-TL00C01B160 permiten a atacantes obtener privilegios de root o bloquear el sistema o ejecutar código arbitrario, relacionado con un desbordamiento de búfer."
    }
  ],
  "lastModified": "2026-06-17T00:54:59.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:nem-al10_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DDA2BFF-6FC8-4FC5-AC9A-3C8CA3C33C88"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:nem-al10:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FC04B249-E16D-4305-A31B-87BA0594D304"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:nem-l51_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C0F0C30-0E89-48BF-81C8-5A43589D54E8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:nem-l51:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "785A5B9C-C3E9-4C77-8D26-AFDC3D43B889"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:nem-l21_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85CFA1EE-35CA-430F-986B-93069BEEE787"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:nem-l21:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FCD4D9F9-0E0B-4465-9EE2-AD006F9D1A57"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:nem-l22_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD0FAA2D-47C7-4F04-83B7-37777346ECDE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:nem-l22:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7BED9616-DFA1-4582-B5D4-735818368B9C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}