ID

VAR-201609-0050


CVE

CVE-2016-6179


TITLE

Huawei Honor6 Smartphone software WiFi Service disruption in drivers (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2016-004563

DESCRIPTION

The WiFi driver in Huawei Honor 6 smartphones with software H60-L01 before H60-L01C00B850, H60-L11 before H60-L11C00B850, H60-L21 before H60-L21C00B850, H60-L02 before H60-L02C00B850, H60-L12 before H60-L12C00B850, and H60-L03 before H60-L03C01B850 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application. Supplementary information : CWE Vulnerability type by CWE-284: Improper Access Control ( Inappropriate access control ) Has been identified. http://cwe.mitre.org/data/definitions/284.htmlDenial of service operations through a specially crafted application by an attacker ( System crash ) It may be put into a state or it may be authorized. HuaweiHonor6 is a smartphone product. Huawei Honor6 Smart Phone is prone to a local privilege-escalation vulnerability. An input validation vulnerability exists in the WiFi driver in Huawei Honor6. The following versions are affected: Huawei Honor6 before H60-L01C00B850, before H60-L11C00B850, before H60-L21C00B850, before H60-L02C00B850, before H60-L12C00B850, before H60-L03C01B850

Trust: 2.52

sources: NVD: CVE-2016-6179 // JVNDB: JVNDB-2016-004563 // CNVD: CNVD-2016-05049 // BID: 91773 // VULHUB: VHN-94999

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05049

AFFECTED PRODUCTS

vendor:huaweimodel:honor 6scope:eqversion:h60-l02c00b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:eqversion:h60-l03c01b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:eqversion:h60-l21c00b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:eqversion:h60-l11c00b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:eqversion:h60-l01c00b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:eqversion:h60-l12c00b850

Trust: 1.4

vendor:huaweimodel:honor 6scope:gteversion:h60-l02

Trust: 1.0

vendor:huaweimodel:honor 6scope:gteversion:h60-l01

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l03c01b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l01c00b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:gteversion:h60-l11

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l12c00b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l02c00b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:gteversion:h60-l12

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l11c00b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:gteversion:h60-l03

Trust: 1.0

vendor:huaweimodel:honor 6scope:gteversion:h60-l21

Trust: 1.0

vendor:huaweimodel:honor 6scope:lteversion:h60-l21c00b850

Trust: 1.0

vendor:huaweimodel:honor 6scope:ltversion:h60-l21

Trust: 0.8

vendor:huaweimodel:honor 6scope:ltversion:h60-l03

Trust: 0.8

vendor:huaweimodel:honor 6scope:ltversion:h60-l01

Trust: 0.8

vendor:huaweimodel:honor 6scope: - version: -

Trust: 0.8

vendor:huaweimodel:honor 6scope:ltversion:h60-l12

Trust: 0.8

vendor:huaweimodel:honor 6scope:ltversion:h60-l02

Trust: 0.8

vendor:huaweimodel:honor 6scope:ltversion:h60-l11

Trust: 0.8

vendor:huaweimodel:honor6 <h60-l01c00b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6 <h60-l11c00b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6 <h60-l21c00b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6 <h60-l02c00b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6 <h60-l12c00b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6 <h60-l03c01b850scope: - version: -

Trust: 0.6

vendor:huaweimodel:honor6scope:eqversion:0

Trust: 0.3

vendor:huaweimodel:honor6 h60-l21c00b850scope:neversion: -

Trust: 0.3

vendor:huaweimodel:honor6 h60-l12c00b850scope:neversion: -

Trust: 0.3

vendor:huaweimodel:honor6 h60-l11c00b850scope:neversion: -

Trust: 0.3

vendor:huaweimodel:honor6 h60-l03c01b850scope:neversion: -

Trust: 0.3

vendor:huaweimodel:honor6 h60-l02c00b850scope:neversion: -

Trust: 0.3

vendor:huaweimodel:honor6 h60-l01c00b850scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2016-05049 // BID: 91773 // JVNDB: JVNDB-2016-004563 // CNNVD: CNNVD-201607-414 // NVD: CVE-2016-6179

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-6179
value: HIGH

Trust: 1.0

NVD: CVE-2016-6179
value: HIGH

Trust: 0.8

CNVD: CNVD-2016-05049
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201607-414
value: HIGH

Trust: 0.6

VULHUB: VHN-94999
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-6179
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2016-05049
severity: MEDIUM
baseScore: 6.2
vectorString: AV:L/AC:H/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-94999
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-6179
baseSeverity: HIGH
baseScore: 7.0
vectorString: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.0
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-05049 // VULHUB: VHN-94999 // JVNDB: JVNDB-2016-004563 // CNNVD: CNNVD-201607-414 // NVD: CVE-2016-6179

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-94999 // JVNDB: JVNDB-2016-004563 // NVD: CVE-2016-6179

THREAT TYPE

local

Trust: 0.9

sources: BID: 91773 // CNNVD: CNNVD-201607-414

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-201607-414

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-004563

PATCH

title:huawei-sa-20160713-01-smartphoneurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160713-01-smartphone-en

Trust: 0.8

title:HuaweiHonor6SmartPhone local privilege escalation patchurl:https://www.cnvd.org.cn/patchInfo/show/79350

Trust: 0.6

title:Huawei Honor6 Smart Phone Remedial measures for local privilege escalationurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=62959

Trust: 0.6

sources: CNVD: CNVD-2016-05049 // JVNDB: JVNDB-2016-004563 // CNNVD: CNNVD-201607-414

EXTERNAL IDS

db:NVDid:CVE-2016-6179

Trust: 3.4

db:BIDid:91773

Trust: 2.6

db:JVNDBid:JVNDB-2016-004563

Trust: 0.8

db:CNNVDid:CNNVD-201607-414

Trust: 0.7

db:CNVDid:CNVD-2016-05049

Trust: 0.6

db:VULHUBid:VHN-94999

Trust: 0.1

sources: CNVD: CNVD-2016-05049 // VULHUB: VHN-94999 // BID: 91773 // JVNDB: JVNDB-2016-004563 // CNNVD: CNNVD-201607-414 // NVD: CVE-2016-6179

REFERENCES

url:http://www.securityfocus.com/bid/91773

Trust: 2.3

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160713-01-smartphone-en

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-6179

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-6179

Trust: 0.8

url:http://www.huawei.com

Trust: 0.3

sources: CNVD: CNVD-2016-05049 // VULHUB: VHN-94999 // BID: 91773 // JVNDB: JVNDB-2016-004563 // CNNVD: CNNVD-201607-414 // NVD: CVE-2016-6179

CREDITS

Xiao Peng and Song Yang of Alibaba Mobile Security Team.,Yang Chengming, Yang Chao, You Ning

Trust: 0.6

sources: CNNVD: CNNVD-201607-414

SOURCES

db:CNVDid:CNVD-2016-05049
db:VULHUBid:VHN-94999
db:BIDid:91773
db:JVNDBid:JVNDB-2016-004563
db:CNNVDid:CNNVD-201607-414
db:NVDid:CVE-2016-6179

LAST UPDATE DATE

2024-11-23T23:05:35.046000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05049date:2016-07-21T00:00:00
db:VULHUBid:VHN-94999date:2019-05-30T00:00:00
db:BIDid:91773date:2016-07-13T00:00:00
db:JVNDBid:JVNDB-2016-004563date:2016-09-09T00:00:00
db:CNNVDid:CNNVD-201607-414date:2019-05-31T00:00:00
db:NVDid:CVE-2016-6179date:2024-11-21T02:55:36.817

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05049date:2016-07-21T00:00:00
db:VULHUBid:VHN-94999date:2016-09-07T00:00:00
db:BIDid:91773date:2016-07-13T00:00:00
db:JVNDBid:JVNDB-2016-004563date:2016-09-09T00:00:00
db:CNNVDid:CNNVD-201607-414date:2016-07-15T00:00:00
db:NVDid:CVE-2016-6179date:2016-09-07T20:59:02.920