CVE-2017-15311
Summary
| CVE | CVE-2017-15311 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-22 17:29:00 UTC |
| Updated | 2018-01-09 17:22:00 UTC |
| Description | The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker could exploit this vulnerability to perform a denial of service attack or remote code execution in baseband module. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Mate 10 | - | All | All | All |
| Hardware | Huawei | Mate 10 | - | All | All | All |
| Operating System | Huawei | Mate 10 Firmware | All | All | All | All |
| Operating System | Huawei | Mate 10 Firmware | All | All | All | All |
| Hardware | Huawei | Mate 10 Pro | - | All | All | All |
| Hardware | Huawei | Mate 10 Pro | - | All | All | All |
| Operating System | Huawei | Mate 10 Pro Firmware | All | All | All | All |
| Operating System | Huawei | Mate 10 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Mate 9 | - | All | All | All |
| Hardware | Huawei | Mate 9 | - | All | All | All |
| Operating System | Huawei | Mate 9 Firmware | All | All | All | All |
| Operating System | Huawei | Mate 9 Firmware | All | All | All | All |
| Hardware | Huawei | Mate 9 Pro | - | All | All | All |
| Hardware | Huawei | Mate 9 Pro | - | All | All | All |
| Operating System | Huawei | Mate 9 Pro Firmware | All | All | All | All |
| Operating System | Huawei | Mate 9 Pro Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Stack Overflow Vulnerability in Baseband Module of Some Huawei Smart Phones | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.