This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Apps on Huawei Ascend P6 mobile phones can capture screens without the root permission. As a result, user information can be leaked by malware on Ascend P6 mobile phones. (Vulnerability ID: HWPSIRT-2014-0893).
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8571.
Product Name |
Affected Version |
Resolved Product and Version |
EDGE-U00 |
V100R001C17B508SP01 and earlier versions |
V100R001C17B508SP02 |
EDGE-T00 |
V100R001C01B508SP01 and earlier versions |
V100R001C01B508SP02 |
EDGE-C00 |
V100R001C92B508SP02 and earlier versions |
V100R001C92B508SP03 |
User information can be stolen by malware on Ascend P6 mobile phones.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Temporal Score: 4.1 (E:F/RL:O/RC:C)
1. Prerequisite:
The attacker must trick the user into installing the malware provided by the attacker.
2. Attacking procedure:
The malware on mobile phones keeps capturing screens and sending them to the attacker.
This vulnerability was found by Chen Jialin. Huawei PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Huawei express our appreciation for Chen Jialin’s concerns on Huawei products.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2014-11-04 V1.2 UPDATED Added the CVE ID
2014-10-08 V1.1 UPDATED Updated the information of “Affected Products”
2014-09-23 V1.0 INITIALNone