CVE-2017-2729 is a buffer overflow vulnerability affecting the bootloaders of Huawei Honor 5A and P8 Lite smartphones running specific older software versions. An attacker with root privileges on the Android system could trick a user into installing a malicious application. This application could then modify data to trigger a buffer overflow upon the next system reboot, leading to continuous reboots or arbitrary code execution. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< cam-tl00c01b193CPE matchmatch criteria | cpe:2.3:o:huawei:honor_5a_firmware:*:*:*:*:*:*:*:* | ||
< cam-tl00hc00b193CPE matchmatch criteria | cpe:2.3:o:huawei:honor_5a_firmware:*:*:*:*:*:*:*:* | ||
< cam-ul00c00b193CPE matchmatch criteria | cpe:2.3:o:huawei:honor_5a_firmware:*:*:*:*:*:*:*:* | ||
< ale-l02c635b568CPE matchmatch criteria | cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* | ||
< ale-l21c10b541CPE matchmatch criteria | cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.