Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-17176

Quick assessment

Affected
Huawei Technologies Co., Ltd. Mate 9, Mate 9 Pro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Huawei Mate 9和Mate 9 Pro都是中国华为(Huawei)公司的智能手机产品。hardware security module是其中的一个硬件安全模块。 Huawei Mate 9和Mate 9 Pro中的hardware security模块存在安全漏洞。攻击者可利用该漏洞以系统root权限在TrustZone中读写任意位置的内存数据或执行任意代码。以下产品和版本受到影响:Huawei Mate 9 MHA-AL00BC00B156之前的版本,MHA-CL00BC00B156之前的版本

AI Predicted 8.1 Difficulty: Moderate EPSS 0.31% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-17176

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Huawei Mate 9和Mate 9 Pro hardware security模块安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Huawei Mate 9和Mate 9 Pro都是中国华为(Huawei)公司的智能手机产品。hardware security module是其中的一个硬件安全模块。 Huawei Mate 9和Mate 9 Pro中的hardware security模块存在安全漏洞。攻击者可利用该漏洞以系统root权限在TrustZone中读写任意位置的内存数据或执行任意代码。以下产品和版本受到影响:Huawei Mate 9 MHA-AL00BC00B156之前的版本,MHA-CL00BC00B156之前的版本
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Huawei Technologies Co., Ltd. Mate 9, Mate 9 Pro Versions earlier before MHA-AL00BC00B156, Versions earlier before MHA-CL00BC00B156, Versions earlier before MHA-DL00BC00B156, Versions earlier before MHA-TL00BC00B156, Versions earlier before LON-AL00BC00B156, Versions earlier before LON-CL00BC00B156, Ver -

II. Public POCs for CVE-2017-17176

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-17176

请登录查看更多情报信息。

Other References for CVE-2017-17176 (1)

Same Patch Batch · Huawei Technologies Co., Ltd. · 2018-10-17 · 3 CVEs total

CVE-2018-7924 Huawei Anne-AL00 信息泄露漏洞
CVE-2018-7989 Huawei Mate 10 Pro 授权问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-17176

No comments yet


Leave a comment