CVE-2017-8172 Details
Description
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a out-of-bounds array access that results in smart phone restart.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170628-01-isub-en | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/99370 | CVE | Third Party AdvisoryVDB Entry |
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170628-01-isub-en | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/99370 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-129 | Improper Validation of Array Index | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| huawei p10 plus firmware | < vky-al00c00b157 |
CPE
Remediation
| |
| huawei p10 plus | All versions |
CPE
Remediation
| |
| huawei p10 firmware | < vtr-al00c00b157 |
CPE
Remediation
| |
| huawei p10 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 12, 2017 | Initial Analysis | [email protected] |
| Nov 24, 2017 | CVE Modified | [email protected] |