VulnerabilityModified
CVE-2017-2694
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call.
LOW 3.3EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
- CVSS 3.0
- 3.3 LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-275
- Affected
- huawei/vmall
- Source
- psirt@huawei.com
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-vmall-enVendor Advisory
- http://www.securityfocus.com/bid/95915Third Party Advisory, VDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-vmall-enVendor Advisory
- http://www.securityfocus.com/bid/95915Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.