CVE-2017-2699
CVE-2017-2699
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
22 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Affected products
Huawei Technologies Co., Ltd. · Honor 7, Mate S,LYO-L21Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →