CVE-2017-15311
Summary
| CVE | CVE-2017-15311 |
|---|---|
| State | PUBLISHED |
| Assigner | huawei |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-22 17:29:13 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker could exploit this vulnerability to perform a denial of service attack or remote code execution in baseband module. |
Risk And Classification
Primary CVSS: v3.0 8.8 HIGH from [email protected]
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-119 | Stack Overflow
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 5.8 | AV:A/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:A/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Mate 10 | - | All | All | All |
| Operating System | Huawei | Mate 10 Firmware | All | All | All | All |
| Hardware | Huawei | Mate 10 Pro | - | All | All | All |
| Operating System | Huawei | Mate 10 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Mate 9 | - | All | All | All |
| Operating System | Huawei | Mate 9 Firmware | All | All | All | All |
| Hardware | Huawei | Mate 9 Pro | - | All | All | All |
| Operating System | Huawei | Mate 9 Pro Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Huawei Technologies Co. Ltd. | Mate 10 | affected before ALP-AL00 8.0.0.120(SP2C00) | Not specified |
| CNA | Huawei Technologies Co. Ltd. | Mate 10 Pro | affected before BLA-AL00 8.0.0.120(SP2C00) | Not specified |
| CNA | Huawei Technologies Co. Ltd. | Mate 9 | affected before MHA-AL00B 8.0.0.334(C00) | Not specified |
| CNA | Huawei Technologies Co. Ltd. | Mate 9 Pro | affected before LON-AL00B 8.0.0.334(C00), | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Stack Overflow Vulnerability in Baseband Module of Some Huawei Smart Phones | af854a3a-2127-422b-91ae-364da2661108 | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.