製品・ソフトウェアに関する情報
複数の Huawei スマートフォンのソフトウェアにおけるパストラバーサルの脆弱性
Title 複数の Huawei スマートフォンのソフトウェアにおけるパストラバーサルの脆弱性
Summary

複数の Huawei スマートフォンのソフトウェアには、パストラバーサルの脆弱性が存在します。

Possible impacts 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Jan. 25, 2017, midnight
Registration Date Dec. 15, 2017, 4:27 p.m.
Last Update Dec. 15, 2017, 4:27 p.m.
CVSS3.0 : 重要
Score 7.8
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS2.0 : 警告
Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected System
Huawei
G8 ファームウェア 
Honor 6 ファームウェア 
Honor 7 ファームウェア 
Mate 7 ファームウェア 
Mate S ファームウェア 
P8 Lite ファームウェア 
P8 ファームウェア 
SHOTX ファームウェア 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2017年12月15日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2017-2693
Summary

ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a path traversal vulnerability. An attacker may exploit it to decompress malicious files into a target path.

Publication Date Nov. 23, 2017, 4:29 a.m.
Registration Date Jan. 26, 2021, 1:22 p.m.
Last Update Nov. 21, 2024, 12:23 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l02c635b140
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l02c636b140
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l21c10b150
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l21c185b200
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l21c432b214
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l21c464b150
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l21c636b200
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-l23c605b190
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-tl00c01b250
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* ale-ul00c00b250.
execution environment
1 cpe:2.3:h:huawei:p8_lite:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:* mt7-l09c605b325
execution environment
1 cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:* mt7-l09c900b339
execution environment
1 cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:huawei:mate_7_firmware:*:*:*:*:*:*:*:* mt7-tl10c900b339
execution environment
1 cpe:2.3:h:huawei:mate_7:-:*:*:*:*:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:* crr-cl00c92b172
execution environment
1 cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:* crr-l09c432b180
execution environment
1 cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:* crr-tl00c01b172
execution environment
1 cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:* crr-ul00c00b172
execution environment
1 cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:huawei:mate_s_firmware:*:*:*:*:*:*:*:* crr-ul20c432b171
execution environment
1 cpe:2.3:h:huawei:mate_s:-:*:*:*:*:*:*:*
Configuration19 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-cl00c92b230
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration20 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-l09c432b222
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration21 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-tl00c01b230sp01
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration22 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-ul00c00b230
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration23 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-ul00c10b201
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration24 or higher or less more than less than
cpe:2.3:o:huawei:p8_firmware:*:*:*:*:*:*:*:* gra-ul00c432b220
execution environment
1 cpe:2.3:h:huawei:p8:-:*:*:*:*:*:*:*
Configuration25 or higher or less more than less than
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:* h60-l04c10b523
execution environment
1 cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*
Configuration26 or higher or less more than less than
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:* h60-l04c185b523
execution environment
1 cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*
Configuration27 or higher or less more than less than
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:* h60-l04c636b527
execution environment
1 cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*
Configuration28 or higher or less more than less than
cpe:2.3:o:huawei:honor_6_firmware:*:*:*:*:*:*:*:* h60-l04c900b530
execution environment
1 cpe:2.3:h:huawei:honor_6:-:*:*:*:*:*:*:*
Configuration29 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-al10c00b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration30 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-al10c92b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration31 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-cl00c92b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration32 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-l01c10b140
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration33 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-l01c10b140
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration34 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-l01c432b187
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration35 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-l01c432b190
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration36 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-l01c636b130
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration37 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-tl00c01b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration38 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-tl01hc01b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration39 or higher or less more than less than
cpe:2.3:o:huawei:honor_7_firmware:*:*:*:*:*:*:*:* plk-ul00c17b220
execution environment
1 cpe:2.3:h:huawei:honor_7:-:*:*:*:*:*:*:*
Configuration40 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-al00c92b200
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration41 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-cl00c92b210
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration42 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-tl00c01b210
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration43 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-tl00hc01b210
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration44 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-ul00c00b210
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration45 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* rio-al00c00b220
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration46 or higher or less more than less than
cpe:2.3:o:huawei:shotx_firmware:*:*:*:*:*:*:*:* ath-al00c00b210
execution environment
1 cpe:2.3:h:huawei:shotx:-:*:*:*:*:*:*:*
Configuration47 or higher or less more than less than
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:* rio-al00c00b220
execution environment
1 cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*
Configuration48 or higher or less more than less than
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:* rio-cl00c92b220
execution environment
1 cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*
Configuration49 or higher or less more than less than
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:* rio-tl00c01b220
execution environment
1 cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*
Configuration50 or higher or less more than less than
cpe:2.3:o:huawei:g8_firmware:*:*:*:*:*:*:*:* rio-ul00c00b220
execution environment
1 cpe:2.3:h:huawei:g8:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List