CVE-2014-2271
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
cn.wps.moffice.common.beans.print.CloudPrintWebView en Kingsoft Office versión 5.3.1, como es usado en los dispositivos Huawei P2 versiones anteriores a V100R001C00B043, vuelve a HTTP cuando la conexión HTTPS presenta un fallo en el registro, lo que permite a atacantes de tipo man-in-the-middle dirigir ataques de degradación y ejecutar código Java arbitrario mediante el aprovechamiento de una posición de red entre el cliente y el registro para bloquear el tráfico HTTPS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-04 CVE Reserved
- 2020-01-14 CVE Published
- 2024-06-11 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-401529.htm | Third Party Advisory | |
http://www.securityfocus.com/bid/71381 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99089 | Third Party Advisory | |
https://labs.f-secure.com/advisories/kingsoft-office-remote-code-execution | Third Party Advisory | |
https://labs.f-secure.com/assets/763/original/mwri_advisory_huawei_kingsoft-office.pdf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | P2-6011 Firmware Search vendor "Huawei" for product "P2-6011 Firmware" | < v100r001c00b043 Search vendor "Huawei" for product "P2-6011 Firmware" and version " < v100r001c00b043" | - |
Affected
| in | Huawei Search vendor "Huawei" | P2-6011 Search vendor "Huawei" for product "P2-6011" | - | - |
Safe
|
Wps Search vendor "Wps" | Wps Office Search vendor "Wps" for product "Wps Office" | 5.3.1 Search vendor "Wps" for product "Wps Office" and version "5.3.1" | - |
Affected
|