Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
2016-09-07T19:28:13.380
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei_firmware | s12700 | v200r005c00 | Yes |
Hardware | huawei | s12700 | - | No |
Operating System | huawei | s9700_firmware | v200r003c00 | Yes |
Operating System | huawei | s9700_firmware | v200r005c00 | Yes |
Hardware | huawei | s9700 | - | No |
Operating System | huawei | s7700_firmware | v200r003c00 | Yes |
Operating System | huawei | s7700_firmware | v200r005c00 | Yes |
Hardware | huawei | s7700 | - | No |
Operating System | huawei | s9300_firmware | v200r003c00 | Yes |
Operating System | huawei | s9300_firmware | v200r005c00 | Yes |
Hardware | huawei | s9300 | - | No |