Lucene search

K
cveHuaweiCVE-2017-8174
HistoryNov 22, 2017 - 7:29 p.m.

CVE-2017-8174

2017-11-2219:29:04
CWE-326
huawei
web.nvd.nist.gov
29
huawei
usg6300
usg6600
software
v100r001c30spc300
v100r001c30spc500
v100r001c30spc600
v100r001c30spc700
v100r001c30spc800
weak algorithm
vulnerability
cve-2017-8174
nvd
information leak
confidential
data breach
encryption

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

56.3%

Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and cause confidential information leaks on the transmission links.

Affected configurations

Nvd
Vulners
Node
huaweisecospace_usg6300_firmwareMatchv100r001c30spc300
AND
huaweisecospace_usg6300Match-
Node
huaweisecospace_usg6600_firmwareMatchv100r001c30spc500
OR
huaweisecospace_usg6600_firmwareMatchv100r001c30spc600
OR
huaweisecospace_usg6600_firmwareMatchv100r001c30spc700
OR
huaweisecospace_usg6600_firmwareMatchv100r001c30spc800
AND
huaweisecospace_usg6600Match-
VendorProductVersionCPE
huaweisecospace_usg6300_firmwarev100r001c30spc300cpe:2.3:o:huawei:secospace_usg6300_firmware:v100r001c30spc300:*:*:*:*:*:*:*
huaweisecospace_usg6300-cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev100r001c30spc500cpe:2.3:o:huawei:secospace_usg6600_firmware:v100r001c30spc500:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev100r001c30spc600cpe:2.3:o:huawei:secospace_usg6600_firmware:v100r001c30spc600:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev100r001c30spc700cpe:2.3:o:huawei:secospace_usg6600_firmware:v100r001c30spc700:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev100r001c30spc800cpe:2.3:o:huawei:secospace_usg6600_firmware:v100r001c30spc800:*:*:*:*:*:*:*
huaweisecospace_usg6600-cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Secospace USG6300,Secospace USG6600",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "V100R001C30SPC300,V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

56.3%

Related for CVE-2017-8174