CVE-2017-2692

The Keyguard application in ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a privilege elevation vulnerability. An attacker may exploit it to launch command injection in order to gain elevated privileges.
References
Link Resource
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-emui-en Issue Tracking Vendor Advisory
http://www.securityfocus.com/bid/95919 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*

Information

Published : 2017-11-22 11:29

Updated : 2017-12-07 10:56


NVD link : CVE-2017-2692

Mitre link : CVE-2017-2692


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

huawei

  • p8
  • g8
  • honor_7
  • p8_firmware
  • honor_6_firmware
  • honor_6
  • shotx
  • mate_s_firmware
  • mate_7_firmware
  • p8_lite_firmware
  • shotx_firmware
  • g8_firmware
  • mate_7
  • honor_7_firmware
  • p8_lite
  • mate_s