CVE-2017-2694
CVE-2017-2694
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
22 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
Affected products
Huawei Technologies Co., Ltd. · HwVmallWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →