Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00209.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
Ar120-s
Subscribe
Ar120-s Firmware
Subscribe
Ar1200
Subscribe
Ar1200-s
Subscribe
Ar1200-s Firmware
Subscribe
Ar1200 Firmware
Subscribe
Ar150
Subscribe
Ar150 Firmware
Subscribe
Ar160
Subscribe
Ar160 Firmware
Subscribe
Ar200
Subscribe
Ar200-s
Subscribe
Ar200-s Firmware
Subscribe
Ar200 Firmware
Subscribe
Ar2200
Subscribe
Ar2200-s
Subscribe
Ar2200-s Firmware
Subscribe
Ar2200 Firmware
Subscribe
Ar3200
Subscribe
Ar3200 Firmware
Subscribe
Ar3600
Subscribe
Ar3600 Firmware
Subscribe
Ar510
Subscribe
Ar510 Firmware
Subscribe
Cloudengine 12800
Subscribe
Cloudengine 12800 Firmware
Subscribe
Cloudengine 5800
Subscribe
Cloudengine 5800 Firmware
Subscribe
Cloudengine 6800
Subscribe
Cloudengine 6800 Firmware
Subscribe
Cloudengine 7800
Subscribe
Cloudengine 7800 Firmware
Subscribe
Dp300
Subscribe
Dp300 Firmware
Subscribe
Espace Iad
Subscribe
Espace Iad Firmware
Subscribe
Espace U1981
Subscribe
Espace U1981 Firmware
Subscribe
Espace Usm
Subscribe
Espace Usm Firmware
Subscribe
Smc2.0
Subscribe
Smc2.0 Firmware
Subscribe
Srg1300
Subscribe
Srg1300 Firmware
Subscribe
Srg2300
Subscribe
Srg2300 Firmware
Subscribe
Srg3300
Subscribe
Srg3300 Firmware
Subscribe
Te30
Subscribe
Te30 Firmware
Subscribe
Te60
Subscribe
Te60 Firmware
Subscribe
Viewpoint 8660
Subscribe
Viewpoint 8660 Firmware
Subscribe
Vp9660
Subscribe
Vp9660 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-8467 | Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR160 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR200 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR2200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR2200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR3200 V200R005C32, V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30, AR3600 V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR510 V200R005C32, V200R006C10, V200R007C00, V200R008C20, CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 5800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 6800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 7800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, DP300 V500R002C00, SMC2.0 V100R003C10, V100R005C00, V500R002C00, SRG1300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG2300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG3300 V200R005C32, V200R006C10, V200R007C00, V200R008C20, TE30 V100R001C10, TE60 V100R003C00, V500R002C00, VP9660 V200R001C02, V200R001C30, V500R002C00, ViewPoint 8660 V100R008C02, V100R008C03, eSpace IAD V300R002C01, eSpace U1981 V200R003C20, V200R003C30, eSpace USM V100R001C01, V300R001C00 have a weak cryptography vulnerability. Due to not properly some values in the certificates, an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T20:51:30.593Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2017-17301
No data.
Status : Modified
Published: 2018-02-15T16:29:03.610
Modified: 2024-11-21T03:17:47.340
Link: CVE-2017-17301
No data.
OpenCVE Enrichment
No data.
EUVD