CVE-2017-8146 is a Denial of Service (DoS) vulnerability affecting the call module of Huawei P10 and P10 Plus smartphones running specific older software versions. An attacker could exploit this by tricking a user into installing a malicious application, which then sends crafted parameters to the call module, causing the call and data communication process to crash. Rated 5.5 MEDIUM on CVSSv3.0, this vulnerability requires user interaction (UI:R) and local access (AV:L) to execute, with low attack complexity (AC:L). The primary impact is high availability loss (A:H), as it disrupts communication services. There is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< vtr-al00c00b167CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< vky-al00c00b167CPE matchmatch criteria | cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* | ||
< vtr-tl00c01b167CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< vky-tl00c01b167CPE matchmatch criteria | cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.