Lucene search

K
cveHuaweiCVE-2017-8118
HistoryNov 22, 2017 - 7:29 p.m.

CVE-2017-8118

2017-11-2219:29:02
CWE-200
huawei
web.nvd.nist.gov
31
cve-2017-8118
uma product
v200r001
v300r001
information leak
vulnerability
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.6

Confidence

High

EPSS

0

Percentile

12.6%

The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.

Affected configurations

Nvd
Node
huaweiumaMatchv200r001
OR
huaweiumaMatchv300r001
VendorProductVersionCPE
huaweiumav200r001cpe:2.3:a:huawei:uma:v200r001:*:*:*:*:*:*:*
huaweiumav300r001cpe:2.3:a:huawei:uma:v300r001:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "UMA",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "V200R001 and V300R001"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.6

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2017-8118