CVE-2017-2699
Summary
| CVE | CVE-2017-2699 |
|---|---|
| State | PUBLISHED |
| Assigner | huawei |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-22 19:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001600000 probability, percentile 0.364150000 (date 2026-05-13)
Problem Types: CWE-434 | Privilege Elevation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Honor 7 | - | All | All | All |
| Operating System | Huawei | Honor 7 Firmware | All | All | All | All |
| Hardware | Huawei | Lyo-l21 | - | All | All | All |
| Operating System | Huawei | Lyo-l21 Firmware | All | All | All | All |
| Hardware | Huawei | Mate S | - | All | All | All |
| Operating System | Huawei | Mate S Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Huawei Technologies Co. Ltd. | Honor 7 Mate SLYO-L21 | affected Earlier than PLK-UL00C17B385 versions, Earlier than CRR-L09C432B380 versions, Earlier than LYO-L21C577B128 versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Huawei Honor 7 and Mate S CVE-2017-2699 Arbitrary File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Advisory - Privilege Elevation Vulnerability Caused by Arbitrary File Upload in Huawei Themes | af854a3a-2127-422b-91ae-364da2661108 | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.