Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-17140 Details

Description

Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-200Exposure of Sensitive Information to an Unauthorized Actor[email protected]

Affected Products

ProductVersions
huawei enjoy 5s firmware
< tag-al00c92b170

CPE

  • cpe:2.3:o:huawei:enjoy_5s_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
huawei enjoy 5s
All versions

CPE

  • cpe:2.3:h:huawei:enjoy_5s:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
huawei y6 pro firmware
< tit-l01c576b121

CPE

  • cpe:2.3:o:huawei:y6_pro_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
huawei y6 pro
All versions

CPE

  • cpe:2.3:h:huawei:y6_pro:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-17140
NVD Published Date:
Mar 5, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-17140 Details - Not Deferred