CVE-2017-17301 Information

Description

Huawei AR120-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR1200 V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR1200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR150 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR160 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR200 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR2200 V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR2200-S V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR3200 V200R005C32 V200R006C10 V200R006C11 V200R007C00 V200R007C01 V200R007C02 V200R008C00 V200R008C10 V200R008C20 V200R008C30 AR3600 V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR510 V200R005C32 V200R006C10 V200R007C00 V200R008C20 CloudEngine 12800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 5800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 6800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 7800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 DP300 V500R002C00 SMC2.0 V100R003C10 V100R005C00 V500R002C00 SRG1300 V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG2300 V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG3300 V200R005C32 V200R006C10 V200R007C00 V200R008C20 TE30 V100R001C10 TE60 V100R003C00 V500R002C00 VP9660 V200R001C02 V200R001C30 V500R002C00 ViewPoint 8660 V100R008C02 V100R008C03 eSpace IAD V300R002C01 eSpace U1981 V200R003C20 V200R003C30 eSpace USM V100R001C01 V300R001C00 have a weak cryptography vulnerability. Due to not properly some values in the certificates an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171222-01-cryptography-en

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: