CVE-2017-2739
low
CVSS v3
3.1
CVSS v2
2.9
VIR risk
3.1
Description
The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP. A man in the middle (MITM) can tamper with the upgrade package of Huawei Vmall APP, and to implant the malicious applications.
Predictions
Exploit likelihood
32%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170208-01-vmall-en
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| huawei | vmall | {"endExcluding":"1.5.3.0"} | 1.5.3.0 |
References
CWEs
CWE-494
Verify integrity in audit chain (admin only). AS-IS.