// For flags

CVE-2017-2704

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and earlier versions,HwCloudDrive(EMUI6.0) 8.0.0.307 and earlier versions,HwPhoneFinder(EMUI6.0) 9.3.0.310 and earlier versions,HwPhoneFinder(EMUI5.1) 9.2.2.303 and earlier versions,HiCinema 8.0.2.300 and earlier versions,HuaweiWear 21.0.0.360 and earlier versions,HiHealthApp 3.0.3.300 and earlier versions have an information exposure vulnerability. Encryption keys are stored in the system. The attacker can implement reverse engineering to obtain the encryption keys, causing information exposure.

Smarthome 1.0.2.364 y versiones anteriores, HiAPP 7.3.0.303 y anteriores, HwParentControl 2.0.0 y anteriores, HwParentControlParent 5.1.0.12 y anteriores, Crowdtest 1.5.3 y anteriores, HiWallet 8.0.0.301 y anteriores, Huawei Pay 8.0.0.300 y anteriores, Skytone 8.1.2.300 y anteriores, HwCloudDrive(EMUI6.0) 8.0.0.307 y anteriores, HwPhoneFinder(EMUI6.0) 9.3.0.310 y anteriores, HwPhoneFinder(EMUI5.1) 9.2.2.303 y anteriores, HiCinema 8.0.2.300 y anteriores, HuaweiWear 21.0.0.360 y anteriores y HiHealthApp 3.0.3.300 y anteriores tienen una vulnerabilidad de divulgación de información. Las claves de cifrado están almacenadas en el sistema. El atacante puede utilizar ingeniería inversa para obtener las claves de cifrado, provocando una divulgación de información.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2017-11-22 CVE Published
  • 2024-07-28 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
Smarthome
Search vendor "Huawei" for product "Smarthome"
<= 1.0.2.364
Search vendor "Huawei" for product "Smarthome" and version " <= 1.0.2.364"
-
Affected
Huawei
Search vendor "Huawei"
Hiapp
Search vendor "Huawei" for product "Hiapp"
<= 7.3.0.303
Search vendor "Huawei" for product "Hiapp" and version " <= 7.3.0.303"
-
Affected
Huawei
Search vendor "Huawei"
Hwparentcontrol
Search vendor "Huawei" for product "Hwparentcontrol"
<= 2.0.0
Search vendor "Huawei" for product "Hwparentcontrol" and version " <= 2.0.0"
-
Affected
Huawei
Search vendor "Huawei"
Hwparentcontrolparent
Search vendor "Huawei" for product "Hwparentcontrolparent"
<= 5.1.0.12
Search vendor "Huawei" for product "Hwparentcontrolparent" and version " <= 5.1.0.12"
-
Affected
Huawei
Search vendor "Huawei"
Crowdtest
Search vendor "Huawei" for product "Crowdtest"
<= 1.5.3
Search vendor "Huawei" for product "Crowdtest" and version " <= 1.5.3"
-
Affected
Huawei
Search vendor "Huawei"
Hiwallet
Search vendor "Huawei" for product "Hiwallet"
<= 8.0.0.301
Search vendor "Huawei" for product "Hiwallet" and version " <= 8.0.0.301"
-
Affected
Huawei
Search vendor "Huawei"
Huawei Pay
Search vendor "Huawei" for product "Huawei Pay"
<= 8.0.0.300
Search vendor "Huawei" for product "Huawei Pay" and version " <= 8.0.0.300"
-
Affected
Huawei
Search vendor "Huawei"
Skytone
Search vendor "Huawei" for product "Skytone"
<= 8.1.2.300
Search vendor "Huawei" for product "Skytone" and version " <= 8.1.2.300"
-
Affected
Huawei
Search vendor "Huawei"
Hwclouddrive\(emui6.0\)
Search vendor "Huawei" for product "Hwclouddrive\(emui6.0\)"
<= 8.0.0.307
Search vendor "Huawei" for product "Hwclouddrive\(emui6.0\)" and version " <= 8.0.0.307"
-
Affected
Huawei
Search vendor "Huawei"
Hwphonefinder\(emui6.0\)
Search vendor "Huawei" for product "Hwphonefinder\(emui6.0\)"
<= 9.3.0.310
Search vendor "Huawei" for product "Hwphonefinder\(emui6.0\)" and version " <= 9.3.0.310"
-
Affected
Huawei
Search vendor "Huawei"
Hwphonefinder\(emui5.1\)
Search vendor "Huawei" for product "Hwphonefinder\(emui5.1\)"
<= 9.2.2.303
Search vendor "Huawei" for product "Hwphonefinder\(emui5.1\)" and version " <= 9.2.2.303"
-
Affected
Huawei
Search vendor "Huawei"
Hicinema
Search vendor "Huawei" for product "Hicinema"
<= 8.0.2.300
Search vendor "Huawei" for product "Hicinema" and version " <= 8.0.2.300"
-
Affected
Huawei
Search vendor "Huawei"
Huaweiwear
Search vendor "Huawei" for product "Huaweiwear"
<= 21.0.0.360
Search vendor "Huawei" for product "Huaweiwear" and version " <= 21.0.0.360"
-
Affected
Huawei
Search vendor "Huawei"
Hihealthapp
Search vendor "Huawei" for product "Hihealthapp"
<= 3.0.3.300
Search vendor "Huawei" for product "Hihealthapp" and version " <= 3.0.3.300"
-
Affected