CVE-2017-8150 describes an arbitrary memory write vulnerability in the bootloaders of Huawei P10 and P10 Plus phones, affecting specific firmware versions. This flaw, stemming from a lack of parameter validation, could allow an attacker with root privileges to install a malicious application. Upon the next system reboot, this application could modify data, leading to continuous system reboots or arbitrary code execution. Rated with a CVSS score of 7.8 (High), the vulnerability requires user interaction (UI:R) to install a malicious app, but once exploited, it grants high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). The attack complexity is low (AC:L), and it is a local attack (AV:L). Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< victoria-l09ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< victoria-l29ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_firmware:*:*:*:*:*:*:*:* | ||
< vicky-l29ac605b162CPE matchmatch criteria | cpe:2.3:o:huawei:p10_plus_firmware:*:*:*:*:*:*:*:* | ||
< ale-l21c113b566CPE matchmatch criteria | cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* | ||
< eva-l09c432b391CPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.