This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
There has a memory overflow vulnerability in Some Huawei mobile phone products. An attacker may exploit this vulnerability to gain the root access over the mobile phones. Then the attacker can further modify memory data and obtain sensitive information. (Vulnerability ID: HWPSIRT-2015-10046)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-0569,CVE-2015-0570,CVE-2015-0571.
Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/hw-462918
Product Name |
Affected Version |
Resolved Product and Version |
Honor 4A |
SCL-AL00 C00B200 and earlier version |
SCL-AL00 C00B211 |
SCL-TL10H C00B200 and earlier version |
SCL-TL10H C00B211 |
|
SCL-TL10 C01B200 and earlier version |
SCL-TL10 C01B211 |
|
SCL-CL00 C92B200 and earlier version |
SCL-CL00 C92B211 |
Attacker can exploit the vulnerability to obtain the root permission and modify memory data and obtain sensitive information.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 6.2 (AV:L/AC:H/Au:N/C:C/I:C/A:C)
Temporal Score: 5.1 (E:F/RL:O/RC:C)
Overall Score: 5.1
1. Prerequisite:
Attackers must trick users into installing the malware provided by the attackers.
2. Attacking procedure:
The attacker can trick users into installing malicious apps and exploit the vulnerability to obtain the root permission and then can further modify memory data and obtain sensitive information.
This vulnerability was disclosed by Slipper at the GeekPwn Conference on October 2015. Huawei PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2016-01-29 V1.1 UPDATED Assigned a CVE ID to the vulnerability
2015-11-24 V1.0 INITIAL
None