CVE-2017-2706

Description

Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker to replace files and impact the service.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
0.097

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities affected in mate_9_firmware 9.0.1.159(c636e6r1p8t8)NCM
Multiple Vulnerabilities affected in mate_9_firmware 9.0.1.158(c432e6r1p8t8)NCM
Multiple Vulnerabilities affected in mate_9_firmware 8.0.0.356(c00)NCM
Multiple Vulnerabilities affected in mate_9_firmware 8.0.0.129(sp2c00)NCM
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability (CVE-2017-2706)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234