Lucene search

K
cveHuaweiCVE-2017-17325
HistoryMar 09, 2018 - 5:29 p.m.

CVE-2017-17325

2018-03-0917:29:02
huawei
web.nvd.nist.gov
22
huawei
video app
hicinema
8.0.3.308
8.0.4.300
permission control
vulnerability
info leakage

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

29.2%

Huawei video applications HiCinema with software of 8.0.3.308; 8.0.4.300 have a permission control vulnerability. Due to improper verification of specific interface, an attacker who is on the same network with the user can obtain some information through a man-in-the-middle attack.

Affected configurations

Nvd
Vulners
Node
huaweihicinemaMatch8.0.3.308
OR
huaweihicinemaMatch8.0.4.300
AND
huaweihicinemaMatch-
VendorProductVersionCPE
huaweihicinema8.0.3.308cpe:2.3:o:huawei:hicinema:8.0.3.308:*:*:*:*:*:*:*
huaweihicinema8.0.4.300cpe:2.3:o:huawei:hicinema:8.0.4.300:*:*:*:*:*:*:*
huaweihicinema-cpe:2.3:h:huawei:hicinema:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HiCinema",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "8.0.3.308"
      },
      {
        "status": "affected",
        "version": "8.0.4.300"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

29.2%

Related for CVE-2017-17325