René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

313 lines
9.3 KiB
JSON

{
"id": "CVE-2017-2704",
"sourceIdentifier": "psirt@huawei.com",
"published": "2017-11-22T19:29:00.723",
"lastModified": "2020-04-02T16:01:29.010",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and earlier versions,HwCloudDrive(EMUI6.0) 8.0.0.307 and earlier versions,HwPhoneFinder(EMUI6.0) 9.3.0.310 and earlier versions,HwPhoneFinder(EMUI5.1) 9.2.2.303 and earlier versions,HiCinema 8.0.2.300 and earlier versions,HuaweiWear 21.0.0.360 and earlier versions,HiHealthApp 3.0.3.300 and earlier versions have an information exposure vulnerability. Encryption keys are stored in the system. The attacker can implement reverse engineering to obtain the encryption keys, causing information exposure."
},
{
"lang": "es",
"value": "Smarthome 1.0.2.364 y versiones anteriores, HiAPP 7.3.0.303 y anteriores, HwParentControl 2.0.0 y anteriores, HwParentControlParent 5.1.0.12 y anteriores, Crowdtest 1.5.3 y anteriores, HiWallet 8.0.0.301 y anteriores, Huawei Pay 8.0.0.300 y anteriores, Skytone 8.1.2.300 y anteriores, HwCloudDrive(EMUI6.0) 8.0.0.307 y anteriores, HwPhoneFinder(EMUI6.0) 9.3.0.310 y anteriores, HwPhoneFinder(EMUI5.1) 9.2.2.303 y anteriores, HiCinema 8.0.2.300 y anteriores, HuaweiWear 21.0.0.360 y anteriores y HiHealthApp 3.0.3.300 y anteriores tienen una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n. Las claves de cifrado est\u00e1n almacenadas en el sistema. El atacante puede utilizar ingenier\u00eda inversa para obtener las claves de cifrado, provocando una divulgaci\u00f3n de informaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:smarthome:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.0.2.364",
"matchCriteriaId": "FEF1E07C-5A28-4A01-B739-23EF517C6E11"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hiapp:*:*:*:*:*:*:*:*",
"versionEndIncluding": "7.3.0.303",
"matchCriteriaId": "1036F83E-18BA-4560-B796-878F05D976F2"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hwparentcontrol:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.0.0",
"matchCriteriaId": "AD364E0F-4CF9-481D-AAD1-696BEEF8CA9D"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hwparentcontrolparent:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.1.0.12",
"matchCriteriaId": "69572083-6CA3-4FCD-A8F7-460F184BE9A0"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:crowdtest:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.5.3",
"matchCriteriaId": "DD498317-5E9B-4605-A41C-AF411A3F0436"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hiwallet:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.0.0.301",
"matchCriteriaId": "D7ACF69D-3555-4989-A237-EA3F06575E04"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:huawei_pay:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.0.0.300",
"matchCriteriaId": "643D1BE6-9017-4DFE-A733-9772E06BAB5B"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:skytone:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.1.2.300",
"matchCriteriaId": "8FC601A7-493E-4AE4-B26D-21B09CC31D3E"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:hwclouddrive\\(emui6.0\\):*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.0.0.307",
"matchCriteriaId": "6416700B-4AC4-40E1-AA67-070055AC810B"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hwphonefinder\\(emui6.0\\):*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.3.0.310",
"matchCriteriaId": "53B56850-D4CE-4679-B894-3F9F8237125A"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hwphonefinder\\(emui5.1\\):*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.2.2.303",
"matchCriteriaId": "4F537415-D418-48AE-ACFB-CD6F41073492"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hicinema:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.0.2.300",
"matchCriteriaId": "279C86EF-784F-4B46-8E72-5DAFD02C1030"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:huaweiwear:*:*:*:*:*:*:*:*",
"versionEndIncluding": "21.0.0.360",
"matchCriteriaId": "01416564-940A-4842-ADAC-0CA9F53890DB"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:hihealthapp:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.0.3.300",
"matchCriteriaId": "090BA6B7-A16E-4B26-A720-B70D95675369"
}
]
}
]
}
],
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-encryption-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}