9.3
CVSSv2

CVE-2017-2729

Published: 22/11/2017 Updated: 11/12/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The boot loaders in Honor 5A smart phones with software Versions earlier than CAM-TL00C01B193,Versions earlier than CAM-TL00HC00B193,Versions earlier than CAM-UL00C00B193 have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei honor 5a firmware

huawei p8 lite firmware

Github Repositories

BootStomp: a bootloader vulnerability finder

BootStomp BootStomp is a boot-loader bug finder It looks for two different class of bugs: memory corruption and state storage vulnerabilities For more info please refer to the BootStomp paper at seclabcsucsbedu/academic/publishing/#bootstomp-security-bootloaders-mobile-devices-2017 To run BootStomp's analyses, please read the following instructions Note that