CVE-2017-8170 is a buffer overflow vulnerability affecting Huawei smartphones running software versions earlier than VIE-L09C40B360. An attacker can exploit this by tricking a user into installing a malicious application with root privileges, which then sends a specific parameter to the device. This can lead to a denial of service (device restart) or arbitrary code execution, carrying a CVSSv3 score of 7.8 (High) due to its local attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While the vulnerability is severe, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< vie-l09c40b360CPE matchmatch criteria | cpe:2.3:o:huawei:vie-l09_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.