CVE-2017-8208 describes a buffer overflow vulnerability in the driver of Huawei Honor 5C and Honor 6X smartphones with specific older software versions. This flaw, categorized as CWE-119, stems from insufficient parameter validation. An attacker could trick a user into installing a malicious Android application with root privileges, which could then send a specially crafted parameter to the driver, leading to a system reboot or arbitrary code execution. Rated with a CVSS v3 score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) for exploitation, but has a low attack complexity (AC:L). Successful exploitation could result in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< nem-al10c00b356CPE matchmatch criteria | cpe:2.3:o:huawei:honor_5c_firmware:*:*:*:*:*:*:*:* | ||
< berlin-l21hnc432b360CPE matchmatch criteria | cpe:2.3:o:huawei:honor_6x_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.