CVE-2017-17222
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
La función Import Language Package en Huawei eSpace 7950 V200R003C30 y eSpace 8950 V200R003C00 y V200R003C30 tiene una vulnerabilidad de ejecución remota de código. Un atacante remoto autenticado puede manipular y enviar los paquetes a los productos afectados una vez se haya subido el Language Package. Dada la verificación insuficiente de los paquetes, esto podría explotarse para ejecutar código arbitrario.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-04 CVE Reserved
- 2018-03-09 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-01-espace-en | 2018-03-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Espace 7950 Firmware Search vendor "Huawei" for product "Espace 7950 Firmware" | v200r003c30 Search vendor "Huawei" for product "Espace 7950 Firmware" and version "v200r003c30" | - |
Affected
| in | Huawei Search vendor "Huawei" | Espace 7950 Search vendor "Huawei" for product "Espace 7950" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Espace 8950 Firmware Search vendor "Huawei" for product "Espace 8950 Firmware" | v200r003c00 Search vendor "Huawei" for product "Espace 8950 Firmware" and version "v200r003c00" | - |
Affected
| in | Huawei Search vendor "Huawei" | Espace 8950 Search vendor "Huawei" for product "Espace 8950" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Espace 8950 Firmware Search vendor "Huawei" for product "Espace 8950 Firmware" | v200r003c30 Search vendor "Huawei" for product "Espace 8950 Firmware" and version "v200r003c30" | - |
Affected
| in | Huawei Search vendor "Huawei" | Espace 8950 Search vendor "Huawei" for product "Espace 8950" | - | - |
Safe
|