René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

197 lines
6.0 KiB
JSON

{
"id": "CVE-2017-17311",
"sourceIdentifier": "psirt@huawei.com",
"published": "2018-08-21T13:29:00.373",
"lastModified": "2018-10-12T17:01:11.900",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products. Due to improper handling of the malformed messages, an attacker may sent crafted packets to the affected device to exploit these vulnerabilities. Successful exploit the vulnerability could lead to device deny of service."
},
{
"lang": "es",
"value": "Algunos productos Firewall de Huawei, en sus modelos USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR y V300R001C00 tienen una vulnerabilidad de denegaci\u00f3n de servicio (DoS) en las implementaciones IPSEC IKEv1.de productos Firewall de Huawei. Debido a un manejo incorrecto de los mensajes mal formados, un atacante podr\u00eda enviar paquetes manipulados al dispositivo afectado para explotar estas vulnerabilidades. Su explotaci\u00f3n con \u00e9xito podr\u00eda conducir a una denegaci\u00f3n de servicio del dispositivo."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.8
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:usg2205bsr_firmware:v300r001c10spc600:*:*:*:*:*:*:*",
"matchCriteriaId": "B6C9DEE4-F23B-4F54-9868-EDF5AC95D333"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:usg2205bsr:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D9D90A5F-E41D-4CFD-86D2-FB208031CBAB"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:usg2220bsr_firmware:v300r001c00:*:*:*:*:*:*:*",
"matchCriteriaId": "4B8F1406-67A4-4A46-8248-1712E85FE1D9"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:usg2220bsr:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3E4257B6-A1C0-4585-93EF-63081534C5E5"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:usg5120bsr_firmware:v300r001c00:*:*:*:*:*:*:*",
"matchCriteriaId": "54B9E222-40C0-408C-A669-8CF99836FE62"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:usg5120bsr:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9C515743-EA4D-41A6-B295-90EBA5553AD6"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:usg5150bsr_firmware:v300r001c00:*:*:*:*:*:*:*",
"matchCriteriaId": "56E5A858-16C9-4085-BE5A-78A680D2F4D5"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:usg5150bsr:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3F058EF4-A6D4-4931-B571-332E0C1B052D"
}
]
}
]
}
],
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180813-01-Bleichenbacher-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}