CVE-2016-5233
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160520-03-smartphone-en
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.