Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20150919-01-OPENSSL
HistorySep 19, 2015 - 12:00 a.m.

Security Advisory - MITM Vulnerability in the OpenSSL Module of Huawei eSight Network

2015-09-1900:00:00
Huawei Technologies
www.huawei.com
11

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.105 Low

EPSS

Percentile

95.0%

During certificate verification, OpenSSL (starting from version 1.0.1n and 1.0.2b) will attempt to find an alternative certificate chain if the first attempt to build such a chain fails. An error in the implementation of this logic can mean that an attacker could cause certain checks on untrusted certificates to be bypassed. This vulnerability could allow an attacker to launch man-in-the-middle (MITM) attacks and enable applications to regard invalid certificates as valid. (Vulnerability ID: HWPSIRT-2015-07033)

This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-1793.

Affected configurations

Vulners
Node
huaweiesightMatchv300r003c10spc100
CPENameOperatorVersion
esight networkeqV300R003C10SPC100

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.105 Low

EPSS

Percentile

95.0%