2017-12-04 03:02:28 -05:00
|
|
|
{
|
2019-12-23 17:01:08 +00:00
|
|
|
"data_type": "CVE",
|
|
|
|
"data_format": "MITRE",
|
|
|
|
"data_version": "4.0",
|
2019-03-18 03:02:44 +00:00
|
|
|
"CVE_data_meta": {
|
|
|
|
"ID": "CVE-2017-17304",
|
2019-12-23 17:01:08 +00:00
|
|
|
"ASSIGNER": "psirt@huawei.com",
|
2019-03-18 03:02:44 +00:00
|
|
|
"STATE": "PUBLIC"
|
|
|
|
},
|
|
|
|
"affects": {
|
|
|
|
"vendor": {
|
|
|
|
"vendor_data": [
|
|
|
|
{
|
2019-12-23 17:01:08 +00:00
|
|
|
"vendor_name": "n/a",
|
2019-03-18 03:02:44 +00:00
|
|
|
"product": {
|
|
|
|
"product_data": [
|
|
|
|
{
|
2019-12-23 17:01:08 +00:00
|
|
|
"product_name": "DP300, RP200, TE30, TE40, TE50, TE60, eSpace U1981",
|
2019-03-18 03:02:44 +00:00
|
|
|
"version": {
|
|
|
|
"version_data": [
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B010"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B011"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B012"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B013"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B014"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B017"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00B018"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC100"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC200"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC300"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC400"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC500"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC600"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC800"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC900"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPCa00"
|
2019-12-23 17:01:08 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00SPC200"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00SPC300"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00SPC400"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00SPC500"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC300"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC500"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC600"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC700B010"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPC700"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPCb00"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B001"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B002"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B010"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B011"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B012"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B013"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B014"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B016"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B017"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B018"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10B019"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC400"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC700"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC800B011"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V100R001C10SPC900"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPCd00"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V500R002C00SPCe00"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V600R006C00SPC100"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"version_value": "V200R003C20SPC900"
|
2019-03-18 03:02:44 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
2019-12-23 17:01:08 +00:00
|
|
|
}
|
2019-03-18 03:02:44 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
},
|
|
|
|
"problemtype": {
|
|
|
|
"problemtype_data": [
|
|
|
|
{
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
2019-12-23 17:01:08 +00:00
|
|
|
"value": "Input Validation"
|
2019-03-18 03:02:44 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"references": {
|
|
|
|
"reference_data": [
|
|
|
|
{
|
|
|
|
"refsource": "CONFIRM",
|
2019-12-23 17:01:08 +00:00
|
|
|
"name": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-02-cidam-en",
|
|
|
|
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-02-cidam-en"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"description": {
|
|
|
|
"description_data": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
|
|
|
"value": "The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnormal. Affected Huawei Products are: DP300 versions V500R002C00, V500R002C00B010, V500R002C00B011, V500R002C00B012, V500R002C00B013, V500R002C00B014, V500R002C00B017, V500R002C00B018, V500R002C00SPC100, V500R002C00SPC200, V500R002C00SPC300, V500R002C00SPC400, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC800, V500R002C00SPC900, V500R002C00SPCa00; RP200 versions V500R002C00SPC200, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C00SPC400, V600R006C00SPC500; TE30 versions V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700B010, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C00SPC400, V600R006C00SPC500; TE40 versions V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C00SPC400, V600R006C00SPC500; TE50 versions V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C00SPC400, V600R006C00SPC500; TE60 versions V100R001C10, V100R001C10B001, V100R001C10B002, V100R001C10B010, V100R001C10B011, V100R001C10B012, V100R001C10B013, V100R001C10B014, V100R001C10B016, V100R001C10B017, V100R001C10B018, V100R001C10B019, V100R001C10SPC400, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V100R001C10SPC800B011, V100R001C10SPC900, V500R002C00, V500R002C00B010, V500R002C00B011, V500R002C00SPC100, V500R002C00SPC200, V500R002C00SPC300, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC800, V500R002C00SPC900, V500R002C00SPCa00, V500R002C00SPCb00, V500R002C00SPCd00, V500R002C00SPCe00, V600R006C00, V600R006C00SPC100, V600R006C00SPC200, V600R006C00SPC300, V600R006C00SPC400, V600R006C00SPC500; eSpace U1981 version V200R003C20SPC900."
|
2019-03-18 03:02:44 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|