← Back

CVE-2017-2704

nvd nist
Published: Nov 22, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and earlier versions,HwCloudDrive(EMUI6.0) 8.0.0.307 and earlier versions,HwPhoneFinder(EMUI6.0) 9.3.0.310 and earlier versions,HwPhoneFinder(EMUI5.1) 9.2.2.303 and earlier versions,HiCinema 8.0.2.300 and earlier versions,HuaweiWear 21.0.0.360 and earlier versions,HiHealthApp 3.0.3.300 and earlier versions have an information exposure vulnerability. Encryption keys are stored in the system. The attacker can implement reverse engineering to obtain the encryption keys, causing information exposure.

Affected (14)

14 products
Smarthome
Hiapp
Hwparentcontrol
Hwparentcontrolparent
Crowdtest
Hiwallet
Huawei Pay
Skytone
Hwclouddrive(emui6.0)
Hwphonefinder(emui6.0)
Hwphonefinder(emui5.1)
Hicinema
Huaweiwear
Hihealthapp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.2.364
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.3.0.303
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.1.0.12
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.5.3
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.0.301
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.0.300
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.1.2.300
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.0.307
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 9.3.0.310
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 9.2.2.303
Configuration L
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.2.300
Configuration M
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 21.0.0.360
Configuration N
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.0.3.300

Timeline

No history available yet.