CVE-2017-17159

Description

Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.03

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-17159 are affected in mt8-emui4.1_firmware nxt-tl00c01b386sp01NCM
Vulnerabilities CVE-2017-17159 are affected in mt8-emui4.1_firmware nxt-dl00c17b386NCM
Vulnerabilities CVE-2017-17159 are affected in mt8-emui4.1_firmware nxt-cl00c92b386NCM
Vulnerabilities CVE-2017-17159 are affected in mt8-emui4.1_firmware nxt-al10c00b386NCM
Improper Input Validation Vulnerability (CVE-2017-17159)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234