Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-15326


DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an insecure encryption algorithm is negotiated in the communication, an unauthenticated remote attacker can exploit this vulnerability to crack the encrypted data and cause information leakage.


Published

2018-03-23T16:29:00.177

Last Modified

2024-11-21T03:14:28.187

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-327

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei dbs3900_tdd_lte_firmware v100r003c00 Yes
Operating System huawei dbs3900_tdd_lte_firmware v100r004c10 Yes
Hardware huawei dbs3900_tdd_lte - No

References