Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2730

Опубликовано: 22 нояб. 2017
Источник: nvd
CVSS3: 3.5
CVSS2: 2.9
EPSS Низкий

Описание

HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APPs installed access the Wi-Fi hotpot built by attacker, the attacker can collect the information of iPhone mode and firmware version.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:huawei:hilink:*:*:*:*:*:*:*:*
Версия до 5.0.25.306 (исключая)
cpe:2.3:a:huawei:tech_support:*:*:*:*:*:*:*:*
Версия до 5.0.0 (исключая)
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*

EPSS

Процентиль: 11%
0.00037
Низкий

3.5 Low

CVSS3

2.9 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.5
github
больше 3 лет назад

HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APPs installed access the Wi-Fi hotpot built by attacker, the attacker can collect the information of iPhone mode and firmware version.

EPSS

Процентиль: 11%
0.00037
Низкий

3.5 Low

CVSS3

2.9 Low

CVSS2

Дефекты

CWE-200