First published: Thu Feb 15 2018(Updated: )
Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR160 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR200 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR2200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR2200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR3200 V200R005C32, V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30, AR3600 V200R006C10, V200R007C00, V200R007C01, V200R008C20, AR510 V200R005C32, V200R006C10, V200R007C00, V200R008C20, CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 5800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 6800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, CloudEngine 7800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, V200R001C00, DP300 V500R002C00, SMC2.0 V100R003C10, V100R005C00, V500R002C00, SRG1300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG2300 V200R005C32, V200R006C10, V200R007C00, V200R007C02, V200R008C20, SRG3300 V200R005C32, V200R006C10, V200R007C00, V200R008C20, TE30 V100R001C10, TE60 V100R003C00, V500R002C00, VP9660 V200R001C02, V200R001C30, V500R002C00, ViewPoint 8660 V100R008C02, V100R008C03, eSpace IAD V300R002C01, eSpace U1981 V200R003C20, V200R003C30, eSpace USM V100R001C01, V300R001C00 have a weak cryptography vulnerability. Due to not properly some values in the certificates, an unauthenticated remote attacker could forges a specific RSA certificate and exploits the vulnerability to pass identity authentication and logs into the target device to obtain permissions configured for the specific user name.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei AR120-S | =v200r005c32 | |
Huawei AR120-S | =v200r006c10 | |
Huawei AR120-S | =v200r007c00 | |
Huawei AR120-S | =v200r008c20 | |
Huawei AR120 firmware | ||
Huawei ar1200 firmware | =v200r005c20 | |
Huawei ar1200 firmware | =v200r005c32 | |
Huawei ar1200 firmware | =v200r006c10 | |
Huawei ar1200 firmware | =v200r007c00 | |
Huawei ar1200 firmware | =v200r007c01 | |
Huawei ar1200 firmware | =v200r007c02 | |
Huawei ar1200 firmware | =v200r008c20 | |
Huawei AR1200 | ||
Huawei ar1200-s firmware | =v200r005c32 | |
Huawei ar1200-s firmware | =v200r006c10 | |
Huawei ar1200-s firmware | =v200r007c00 | |
Huawei ar1200-s firmware | =v200r008c20 | |
Huawei ar1200-s | ||
Huawei ar150 firmware | =v200r006c10 | |
Huawei ar150 firmware | =v200r007c00 | |
Huawei ar150 firmware | =v200r007c01 | |
Huawei ar150 firmware | =v200r007c02 | |
Huawei ar150 firmware | =v200r008c20 | |
Huawei AR 150 | ||
Huawei AR160 Firmware | =v200r005c32 | |
Huawei AR160 Firmware | =v200r006c10 | |
Huawei AR160 Firmware | =v200r007c00 | |
Huawei AR160 Firmware | =v200r007c01 | |
Huawei AR160 Firmware | =v200r007c02 | |
Huawei AR160 Firmware | =v200r008c20 | |
Huawei AR160 Firmware | ||
Huawei AR200 Firmware | =v200r005c32 | |
Huawei AR200 Firmware | =v200r006c10 | |
Huawei AR200 Firmware | =v200r007c00 | |
Huawei AR200 Firmware | =v200r007c01 | |
Huawei AR200 Firmware | =v200r008c20 | |
Huawei AR200 | ||
Huawei AR200-S Firmware | =v200r005c32 | |
Huawei AR200-S Firmware | =v200r006c10 | |
Huawei AR200-S Firmware | =v200r007c00 | |
Huawei AR200-S Firmware | =v200r007c01 | |
Huawei AR200-S Firmware | =v200r008c20 | |
Huawei AR200-S Firmware | ||
Huawei AR2200 Series Firmware | =v200r005c20 | |
Huawei AR2200 Series Firmware | =v200r005c32 | |
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r007c00 | |
Huawei AR2200 Series Firmware | =v200r007c01 | |
Huawei AR2200 Series Firmware | =v200r007c02 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200 Series Firmware | ||
Huawei AR2200 Series Firmware | =v200r005c32 | |
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r007c00 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200-S | ||
Huawei AR3200 | =v200r005c32 | |
Huawei AR3200 | =v200r006c10 | |
Huawei AR3200 | =v200r006c11 | |
Huawei AR3200 | =v200r007c00 | |
Huawei AR3200 | =v200r007c01 | |
Huawei AR3200 | =v200r007c02 | |
Huawei AR3200 | =v200r008c00 | |
Huawei AR3200 | =v200r008c10 | |
Huawei AR3200 | =v200r008c20 | |
Huawei AR3200 | =v200r008c30 | |
Huawei AR3200 firmware | ||
Huawei AR3600 Firmware | =v200r006c10 | |
Huawei AR3600 Firmware | =v200r007c00 | |
Huawei AR3600 Firmware | =v200r007c01 | |
Huawei AR3600 Firmware | =v200r008c20 | |
Huawei AR3600 Firmware | ||
Huawei AR510 Firmware | =v200r005c32 | |
Huawei AR510 Firmware | =v200r006c10 | |
Huawei AR510 Firmware | =v200r007c00 | |
Huawei AR510 Firmware | =v200r008c20 | |
Huawei AR510 | ||
Huawei CloudEngine 12800 | =v100r003c00 | |
Huawei CloudEngine 12800 | =v100r003c10 | |
Huawei CloudEngine 12800 | =v100r005c00 | |
Huawei CloudEngine 12800 | =v100r005c10 | |
Huawei CloudEngine 12800 | =v100r006c00 | |
Huawei CloudEngine 12800 | =v200r001c00 | |
Huawei CloudEngine 12800 | ||
Huawei CloudEngine 5800 Firmware | =v100r003c00 | |
Huawei CloudEngine 5800 Firmware | =v100r003c10 | |
Huawei CloudEngine 5800 Firmware | =v100r005c00 | |
Huawei CloudEngine 5800 Firmware | =v100r005c10 | |
Huawei CloudEngine 5800 Firmware | =v100r006c00 | |
Huawei CloudEngine 5800 Firmware | =v200r001c00 | |
Huawei CloudEngine 5800 firmware | ||
Huawei CloudEngine 6800 firmware | =v100r003c00 | |
Huawei CloudEngine 6800 firmware | =v100r003c10 | |
Huawei CloudEngine 6800 firmware | =v100r005c00 | |
Huawei CloudEngine 6800 firmware | =v100r005c10 | |
Huawei CloudEngine 6800 firmware | =v100r006c00 | |
Huawei CloudEngine 6800 firmware | =v200r001c00 | |
Huawei CloudEngine 6800 | ||
Huawei CloudEngine 7800 | =v100r003c00 | |
Huawei CloudEngine 7800 | =v100r003c10 | |
Huawei CloudEngine 7800 | =v100r005c00 | |
Huawei CloudEngine 7800 | =v100r005c10 | |
Huawei CloudEngine 7800 | =v100r006c00 | |
Huawei CloudEngine 7800 | =v200r001c00 | |
Huawei CloudEngine 7800 firmware | ||
Huawei DP300 firmware | =v500r002c00 | |
Huawei DP300 firmware | ||
Huawei SMC2.0 firmware | =v100r003c10 | |
Huawei SMC2.0 firmware | =v100r005c00 | |
Huawei SMC2.0 firmware | =v500r002c00 | |
Huawei SMC2.0 | ||
Huawei SRG1300 Firmware | =v200r005c32 | |
Huawei SRG1300 Firmware | =v200r006c10 | |
Huawei SRG1300 Firmware | =v200r007c00 | |
Huawei SRG1300 Firmware | =v200r007c02 | |
Huawei SRG1300 Firmware | =v200r008c20 | |
Huawei SRG1300 | ||
Huawei SRG2300 | =v200r005c32 | |
Huawei SRG2300 | =v200r006c10 | |
Huawei SRG2300 | =v200r007c00 | |
Huawei SRG2300 | =v200r007c02 | |
Huawei SRG2300 | =v200r008c20 | |
Huawei SRG2300 | ||
Huawei SRG3300 | =v200r005c32 | |
Huawei SRG3300 | =v200r006c10 | |
Huawei SRG3300 | =v200r007c00 | |
Huawei SRG3300 | =v200r008c20 | |
Huawei SRG3300 | ||
Huawei TE30 Firmware | =v100r001c10 | |
Huawei TE30 Firmware | ||
Huawei TE60 Firmware | =v100r003c00 | |
Huawei TE60 Firmware | =v500r002c00 | |
Huawei TE60 Firmware | ||
Huawei VP9660 firmware | =v200r001c02 | |
Huawei VP9660 firmware | =v200r001c30 | |
Huawei VP9660 firmware | =v500r002c00 | |
Huawei VP 9660 firmware | ||
Huawei ViewPoint 8660 firmware | =v100r008c02 | |
Huawei ViewPoint 8660 firmware | =v100r008c03 | |
Huawei ViewPoint 8660 | ||
Huawei Espace Integrated Access Device Firmware | =v300r002c01 | |
Huawei eSpace Integrated Access Device | ||
Huawei eSpace U1981 | =v200r003c20 | |
Huawei eSpace U1981 | =v200r003c30 | |
Huawei eSpace unified gateway U1981 | ||
Huawei eSpace USM | =v100r001c01 | |
Huawei eSpace USM | =v300r001c00 | |
Huawei eSpace USM |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17301 has a high severity rating as it involves vulnerabilities in Huawei's routing firmware that could lead to unauthorized access.
To remediate CVE-2017-17301, users should upgrade to the latest firmware version provided by Huawei, specifically addressing the vulnerabilities.
CVE-2017-17301 affects multiple Huawei devices including AR120-S, AR1200, AR150, and several firmware versions listed.
CVE-2017-17301 primarily includes cryptographic weaknesses that can be exploited to compromise the security of affected devices.
While there is no formal workaround for CVE-2017-17301, users are advised to restrict access to affected devices until firmware updates can be applied.