CVE-2017-8149 is an out-of-bounds memory access vulnerability in the bootloaders of specific Huawei P10 and P10 Plus phone models due to insufficient parameter validation. An attacker with root privileges on an Android system could trick a user into installing a malicious application. This application could then modify data, leading to a buffer overflow during the next system reboot, which causes continuous system reboots. Rated as Medium severity (CVSS 5.5), this vulnerability requires user interaction and local access, primarily impacting availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< victoria-l09ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< victoria-l29ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< vicky-l29ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.