Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2735

Опубликовано: 22 нояб. 2017
Источник: nvd
CVSS3: 7.1
CVSS2: 5.8
EPSS Низкий

Описание

TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:y6_pro_firmware:*:*:*:*:*:*:*:*
Версия до tit-al00c583b214 (исключая)
cpe:2.3:h:huawei:y6_pro:-:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00068
Низкий

7.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 7.1
github
больше 3 лет назад

TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.

EPSS

Процентиль: 21%
0.00068
Низкий

7.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-749