Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8213


Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote attackers could exploit this vulnerability to crash the TLS module.


Published

2017-11-22T19:29:05.477

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei smc2.0_firmware v100r003c10 Yes
Operating System huawei smc2.0_firmware v100r005c00spc100 Yes
Operating System huawei smc2.0_firmware v100r005c00spc101b001t Yes
Operating System huawei smc2.0_firmware v100r005c00spc102 Yes
Operating System huawei smc2.0_firmware v100r005c00spc103 Yes
Operating System huawei smc2.0_firmware v100r005c00spc200 Yes
Operating System huawei smc2.0_firmware v100r005c00spc201t Yes
Operating System huawei smc2.0_firmware v500r002c00 Yes
Operating System huawei smc2.0_firmware v600r006c00 Yes
Hardware huawei smc2.0 - No

References