CVE-2017-2699

Description

The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.16

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-ul00c17b220NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-tl01hc01b220NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-tl00c01b220NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-l01c636b130NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-l01c432b190NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-l01c432b187NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-l01c10b140NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-cl00c92b220NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-al10c92b220NCM
Vulnerabilities CVE-2017-2699 are affected in honor_7_firmware plk-al10c00b220NCM
Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-2699)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234