CVE Feed

    Dashboard / CVE / CVE-2017-17138

    CVE-2017-17138

    PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10; V200R007C00; V200R008C00; V200R009C00; V200R010C00; S5700 V200R006C00; V200R007C00; V200R008C00; V200R009C00; V200R010C00; S6700 V200R008C00; V200R009C00; V200R010C00; S7700 V200R007C00; V200R008C00; V200R009C00; V200R010C00; S9700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; Secospace USG6300 V500R001C00; V500R001C30; Secospace USG6500 V500R001C00; V500R001C30; Secospace USG6600 V500R001C00; V500R001C30S; TE30 V100R001C02; V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C01; V100R001C10; V500R002C00; V600R006C00; TP3106 V100R002C00; TP3206 V100R002C00; V100R002C10; USG9500 V500R001C00; V500R001C30; ViewPoint 9030 V100R011C02; V100R011C03 has a DoS vulnerability in PEM module of Huawei products due to insufficient verification. An authenticated local attacker can make processing into deadloop by a malicious certificate. The attacker can exploit this vulnerability to cause a denial of service.

    Published:Mar 5, 2018
    Last Modified:Nov 21, 2024
    EPS:Mar 5, 2018
    EPSS Score:0.00012
    CVSS Score:5.5

    Affected Products

    Vendor
    Huawei
    Product
    Dp300
    Vendor
    Huawei
    Product
    Dp300 Firmware
    Vendor
    Huawei
    Product
    Ips Module
    Vendor
    Huawei
    Product
    Ips Module Firmware
    Vendor
    Huawei
    Product
    Ngfw Module
    Vendor
    Huawei
    Product
    Ngfw Module Firmware
    Vendor
    Huawei
    Product
    Nip6300
    Vendor
    Huawei
    Product
    Nip6300 Firmware
    Vendor
    Huawei
    Product
    Nip6600
    Vendor
    Huawei
    Product
    Nip6600 Firmware
    Vendor
    Huawei
    Product
    Rp200
    Vendor
    Huawei
    Product
    Rp200 Firmware
    Vendor
    Huawei
    Product
    S12700
    Vendor
    Huawei
    Product
    S12700 Firmware
    Vendor
    Huawei
    Product
    S1700
    Vendor
    Huawei
    Product
    S1700 Firmware
    Vendor
    Huawei
    Product
    S2700
    Vendor
    Huawei
    Product
    S2700 Firmware
    Vendor
    Huawei
    Product
    S5700
    Vendor
    Huawei
    Product
    S5700 Firmware
    Vendor
    Huawei
    Product
    S6700
    Vendor
    Huawei
    Product
    S6700 Firmware
    Vendor
    Huawei
    Product
    S7700
    Vendor
    Huawei
    Product
    S7700 Firmware
    Vendor
    Huawei
    Product
    S9700
    Vendor
    Huawei
    Product
    S9700 Firmware
    Vendor
    Huawei
    Product
    Secospace Usg6300
    Vendor
    Huawei
    Product
    Secospace Usg6300 Firmware
    Vendor
    Huawei
    Product
    Secospace Usg6500
    Vendor
    Huawei
    Product
    Secospace Usg6500 Firmware
    Vendor
    Huawei
    Product
    Secospace Usg6600
    Vendor
    Huawei
    Product
    Secospace Usg6600 Firmware
    Vendor
    Huawei
    Product
    Te30
    Vendor
    Huawei
    Product
    Te30 Firmware
    Vendor
    Huawei
    Product
    Te40
    Vendor
    Huawei
    Product
    Te40 Firmware
    Vendor
    Huawei
    Product
    Te50
    Vendor
    Huawei
    Product
    Te50 Firmware
    Vendor
    Huawei
    Product
    Te60
    Vendor
    Huawei
    Product
    Te60 Firmware
    Vendor
    Huawei
    Product
    Tp3106
    Vendor
    Huawei
    Product
    Tp3106 Firmware
    Vendor
    Huawei
    Product
    Tp3206
    Vendor
    Huawei
    Product
    Tp3206 Firmware
    Vendor
    Huawei
    Product
    Usg9500
    Vendor
    Huawei
    Product
    Usg9500 Firmware
    Vendor
    Huawei
    Product
    Viewpoint 9030
    Vendor
    Huawei
    Product
    Viewpoint 9030 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High