Lucene search

K
cveHuaweiCVE-2017-2715
HistoryNov 22, 2017 - 7:29 p.m.

CVE-2017-2715

2017-11-2219:29:01
CWE-200
huawei
web.nvd.nist.gov
25
cve-2017-2715
files app
huawei
mobile phones
brute-force
password cracking
vulnerability
safe key database
unauthorized access
information leak

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper design of the Safe key database. An unauthorized attacker could access sensitive database information and may crack users’ Safe passwords, leading to information leak.

Affected configurations

Nvd
Vulners
Node
huaweifilesRange7.1.1.309
VendorProductVersionCPE
huaweifiles*cpe:2.3:a:huawei:files:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Files £¨Files is the smartphone APP£©",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "7.1.1.309 and earlier versions"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2017-2715