Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.143993
Categoría:Huawei
Título:Huawei Data Communication: Weak Cryptography Vulnerability in Some Huawei Products (huawei-sa-20171222-01-cryptography)
Resumen:Some Huawei products have a weak cryptography vulnerability.
Descripción:Summary:
Some Huawei products have a weak cryptography vulnerability.

Vulnerability Insight:
Some Huawei products have a weak cryptography vulnerability. Due to not properly some values in the certificates, an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name. (Vulnerability ID: HWPSIRT-2016-09014)This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-17301.Huawei has released software updates to fix this vulnerability. This advisory is available in the linked references.

Vulnerability Impact:
An attacker may exploit the vulnerability to forge a specific RSA certificate and log into the target device to obtain permissions configured for the specific user name.

Affected Software/OS:
AR120-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

AR1200 versions V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20

AR1200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

AR150 versions V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20

AR160 versions V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20

AR200 versions V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R008C20

AR200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

AR2200 versions V200R005C20 V200R005C32 V200R006C10 V200R007C00 V200R007C01 V200R007C02 V200R008C20

AR2200-S versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

AR3200 versions V200R005C32 V200R006C10 V200R006C11 V200R007C00 V200R007C01 V200R007C02 V200R008C00 V200R008C10 V200R008C20 V200R008C30

AR3600 versions V200R006C10 V200R007C00 V200R007C01 V200R008C20

AR510 versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

CloudEngine 12800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00

CloudEngine 5800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00

CloudEngine 6800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00

CloudEngine 7800 versions V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 V200R001C00

DBS3900 TDD LTE versions V100R004C10

DP300 versions V500R002C00

SMC2.0 versions V100R003C10 V100R005C00 V500R002C00

SRG1300 versions V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20

SRG2300 versions V200R005C32 V200R006C10 V200R007C00 V200R007C02 V200R008C20

SRG3300 versions V200R005C32 V200R006C10 V200R007C00 V200R008C20

Secospace USG6300 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600

Secospace USG6500 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600

Secospace USG6600 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600

TE30 versions V100R001C10

TE60 versions V100R003C00 V500R002C00

USG9500 versions V500R001C30SPC100 V500R001C30SPC200 V500R001C30SPC600

VP9660 versions V200R001C02 V200R001C30 V500R002C00

ViewPoint 8660 versions V100R008C02 V100R008C03

eSpace IAD versions V300R002C01SPC500B010

eSpace U1981 versions V200R003C20SPH103B010 V200R003C30B015

eSpace USM versions V100R001C01 V300R001C00

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-17301
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.