CVE-2017-17301
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR160 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR200 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR2200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR2200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR3200 V200R005C32, V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30, AR3600 V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR510 V200R005C32, V200R006C10, V200R007C00, V200R008C20, CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 5800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 6800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 7800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, DP300 V500R002C00, SMC2.0 V100R003C10, V100R005C00, V500R002C00, SRG1300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG2300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG3300 V200R005C32, V200R006C10, V200R007C00, V200R008C20, TE30 V100R001C10, TE60 V100R003C00, V500R002C00, VP9660 V200R001C02, V200R001C30, V500R002C00, ViewPoint 8660 V100R008C02, V100R008C03, eSpace IAD V300R002C01, eSpace U1981 V200R003C20, V200R003C30, eSpace USM V100R001C01, V300R001C00 have a weak cryptography vulnerability. Due to not properly some values in the certificates, an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name.
Affected (120)
Products: Huawei: Ar120 S Firmware, Ar1200 Firmware, Ar1200 S Firmware, Ar150 Firmware, Ar160 Firmware, Ar200 Firmware, Ar200 S Firmware, Ar2200 Firmware, Ar2200 S Firmware, Ar3200 Firmware, Ar3600 Firmware, Ar510 Firmware, Cloudengine 12800 Firmware, Cloudengine 5800 Firmware, Cloudengine 6800 Firmware, Cloudengine 7800 Firmware, Dp300 Firmware, Smc2.0 Firmware, Srg1300 Firmware, Srg2300 Firmware, Srg3300 Firmware, Te30 Firmware, Te60 Firmware, Vp9660 Firmware, Viewpoint 8660 Firmware, Espace Iad Firmware, Espace U1981 Firmware, Espace Usm Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar120 S | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c20 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 S | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar160 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 S | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c20 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 S | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar3200 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar3600 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar510 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cloudengine 12800 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cloudengine 5800 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cloudengine 6800 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cloudengine 7800 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Dp300 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Smc2.0 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg1300 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg2300 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r005c32 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg3300 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te30 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te60 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r001c02 |
| Running on/with | Platform Versions |
|---|---|
Huawei Vp9660 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r008c02 |
| Running on/with | Platform Versions |
|---|---|
Huawei Viewpoint 8660 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version v300r002c01 |
| Running on/with | Platform Versions |
|---|---|
Huawei Espace Iad | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r003c20 |
| Running on/with | Platform Versions |
|---|---|
Huawei Espace U1981 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c01 |
| Running on/with | Platform Versions |
|---|---|
Huawei Espace Usm | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.