CVE-2017-2694
low
CVSS v3
3.3
CVSS v2
4.3
VIR risk
3.3
Description
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
Predictions
Exploit likelihood
34%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-vmall-en
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| huawei | vmall | {"endExcluding":"1.5.2.0"} | 1.5.2.0 |
References
CWEs
CWE-275
Verify integrity in audit chain (admin only). AS-IS.