Description
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause out-of-bounds read and write.
Related CPE's
o
huawei
bi-acc-report_firmware
5
o
huawei
cm-h-shark-bd_firmware
34
References
CVSS impact metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
6.1 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2022-09-20T20:15:09.723
2 years agoLast modified
2022-09-22T13:29:44.113
2 years ago