Lucene search

K
cve[email protected]CVE-2017-15352
HistoryFeb 15, 2018 - 4:29 p.m.

CVE-2017-15352

2018-02-1516:29:01
CWE-732
web.nvd.nist.gov
20
huawei
oceanstor
v3
v300r003c20
vulnerability
access control
nvd

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:H/Au:S/C:P/I:N/A:P

3.1 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5500 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5600 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5800 V3, V300R003C00, V300R003C10, V300R003C20 have an improper access control vulnerability. Due to incorrectly restrict access to a resource, an attacker with high privilege may exploit the vulnerability to query some information or send specific message to cause some service abnormal.

Affected configurations

NVD
Node
huaweioceanstor_2800_firmwareMatchv300r003c00
OR
huaweioceanstor_2800_firmwareMatchv300r003c20
AND
huaweioceanstor_2800Match-
Node
huaweioceanstor_5300_firmwareMatchv300r003c00
OR
huaweioceanstor_5300_firmwareMatchv300r003c10
OR
huaweioceanstor_5300_firmwareMatchv300r003c20
AND
huaweioceanstor_5300Match-
Node
huaweioceanstor_5500_firmwareMatchv300r003c00
OR
huaweioceanstor_5500_firmwareMatchv300r003c10
OR
huaweioceanstor_5500_firmwareMatchv300r003c20
AND
huaweioceanstor_5500Match-
Node
huaweioceanstor_5600_firmwareMatchv300r003c00
OR
huaweioceanstor_5600_firmwareMatchv300r003c10
OR
huaweioceanstor_5600_firmwareMatchv300r003c20
AND
huaweioceanstor_5600Match-
Node
huaweioceanstor_5800_firmwareMatchv300r003c00
OR
huaweioceanstor_5800_firmwareMatchv300r003c10
OR
huaweioceanstor_5800_firmwareMatchv300r003c20
AND
huaweioceanstor_5800Match-

CNA Affected

[
  {
    "product": "OceanStor 2800 V3,OceanStor 5300 V3,OceanStor 5500 V3,OceanStor 5600 V3,OceanStor 5800 V3",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "OceanStor 2800 V3 ,V300R003C00 ,V300R003C20 ,OceanStor 5300 V3 ,V300R003C00 ,V300R003C10 ,V300R003C20 ,OceanStor 5500 V3 ,V300R003C00 ,V300R003C10 ,V300R003C20 ,OceanStor 5600 V3 ,V300R003C00 ,V300R003C10 ,V300R003C20 ,OceanStor 5800 V3 ,V300R003C00 ,V300R003C10 ,V300R003C20"
      }
    ]
  }
]

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:H/Au:S/C:P/I:N/A:P

3.1 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Related for CVE-2017-15352