Vulnerability Name: | CVE-2017-8185 (CCN-134654) | ||||||||||||
Assigned: | 2017-09-21 | ||||||||||||
Published: | 2017-09-21 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | ME906s-158 earlier than ME906S_Installer_13.1805.10.3 versions has a privilege elevation vulnerability. An attacker could exploit this vulnerability to modify the configuration information containing malicious files and trick users into executing the files, resulting in the execution of arbitrary code. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-668 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-8185 Source: CONFIRM Type: Vendor Advisory http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170927-01-me906s-en Source: XF Type: UNKNOWN lenovo-cve20178185-priv-esc(134654) Source: CCN Type: Lenovo Security Advisory: LEN-15815 Local Privilege Escalation in Huawei ME906s 4G LTE Mobile Broadband Driver | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |