This security advisory (SA) describes two vulnerabilities.
The decoder driver of P2 was found to allow any application to read or write to an arbitrary memory address. (HWPSIRT-2014-0401)
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-2273.
The Kingsoft Office application comes installed on Huawei P2 devices. An attacker that can modify the traffic coming from the application’s Google Cloud Printing service can gain remote code execution in the context of the application. (HWPSIRT-2014-0402)This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-2271.
Eariler than V100R001C00B043 versions
HWPSIRT-2014-0401: This allows any application running on the device to escalate privileges to root, and can read or write to an arbitrary memory address.HWPSIRT-2014-0402: An attacker can execute code remotely on the victim’s device with the permissions of the Kingsoft Office application.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Temporal Score: 7.7 (E:F/RL:O/RC:C)
Overall Score: 7.7
Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Temporal Score: 5.6 (E:F/RL:O/RC:C)
Overall Score: 5.6
For additional details, customers are advised to reference the website link:
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades, or obtain them through Huawei worldwide website at http://support.huawei.com/support/.
For TAC contact information, please refer to the following links:
TAC for Terminal Customers:http://www.huaweidevice.com/worldwide/netWorkPoint.do?method=index&directoryId=40
This vulnerability is disclosed by MWR infoSecurity Labs. Huawei PSIRT is not aware of any malicious use of the vulnerabilities described in this advisory. Huawei express our appreciation for MWR infoSecurity Labs’s concerns on Huawei products.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.