CVE-2017-17301 Information
Description
Huawei AR120-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR1200 V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR1200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR150 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR160 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR200 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR2200 V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR2200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR3200 V200R005C32 V200R006C10 V200R006C11 V200R007C00 V200R007C01 V200R007C02 V200R008C00 V200R008C10 V200R008C20 V200R008C30 AR3600 V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR510 V200R005C32 V200R006C10 V200R007C00 V200R008C20 CloudEngine 12800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 5800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 6800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 7800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 DP300 V500R002C00 SMC2.0 V100R003C10 V100R005C00 V500R002C00 SRG1300 V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG2300 V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG3300 V200R005C32 V200R006C10 V200R007C00 V200R008C20 TE30 V100R001C10 TE60 V100R003C00 V500R002C00 VP9660 V200R001C02 V200R001C30 V500R002C00 ViewPoint 8660 V100R008C02 V100R008C03 eSpace IAD V300R002C01 eSpace U1981 V200R003C20 V200R003C30 eSpace USM V100R001C01 V300R001C00 have a weak cryptography vulnerability. Due to not properly some values in the certificates an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171222-01-cryptography-en
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: