CVE-2017-2694
—CVSS 3.0
3.3 low
EPSS
<1%p42
Published
()
Modified
Description
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
- Vendors
- huawei
- Products
- vmall
- Weakness
- CWE-275
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.