![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.143993 |
Category: | Huawei |
Title: | Huawei Data Communication: Weak Cryptography Vulnerability in Some Huawei Products (huawei-sa-20171222-01-cryptography) |
Summary: | Some Huawei products have a weak cryptography vulnerability. |
Description: | Summary: Some Huawei products have a weak cryptography vulnerability. Vulnerability Insight: Some Huawei products have a weak cryptography vulnerability. Due to not properly some values in the certificates, an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name. (Vulnerability ID: HWPSIRT-2016-09014)This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-17301.Huawei has released software updates to fix this vulnerability. This advisory is available in the linked references. Vulnerability Impact: An attacker may exploit the vulnerability to forge a specific RSA certificate and log into the target device to obtain permissions configured for the specific user name. Affected Software/OS: AR120-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR1200 versions V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR1200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR150 versions V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR160 versions V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR200 versions V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR2200 versions V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20 AR2200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 AR3200 versions V200R005C32 V200R006C10 V200R006C11 V200R007C00 V200R007C01 V200R007C02 V200R008C00 V200R008C10 V200R008C20 V200R008C30 AR3600 versions V200R006C10 V200R007C00 V200R007C01 V200R008C20 AR510 versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 CloudEngine 12800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 5800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 6800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 CloudEngine 7800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00 DBS3900 TDD LTE versions V100R004C10 DP300 versions V500R002C00 SMC2.0 versions V100R003C10 V100R005C00 V500R002C00 SRG1300 versions V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG2300 versions V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20 SRG3300 versions V200R005C32 V200R006C10 V200R007C00 V200R008C20 Secospace USG6300 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600 Secospace USG6500 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600 Secospace USG6600 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600 TE30 versions V100R001C10 TE60 versions V100R003C00 V500R002C00 USG9500 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600 VP9660 versions V200R001C02 V200R001C30 V500R002C00 ViewPoint 8660 versions V100R008C02 V100R008C03 eSpace IAD versions V300R002C01SPC500B010 eSpace U1981 versions V200R003C20SPH103B010 V200R003C30B015 eSpace USM versions V100R001C01 V300R001C00 Solution: See the referenced vendor advisory for a solution. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-17301 |
Copyright | Copyright (C) 2020 Greenbone Networks GmbH |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |