Input Validation Flaws in CIDAM Protocol Affecting Huawei Devices
CVE-2017-17168

6.5MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
9 March 2018

Summary

The CIDAM Protocol utilized in various Huawei devices is susceptible to multiple input validation flaws. Due to insufficient validation of specific messages, an authenticated remote attacker could exploit these vulnerabilities by sending malicious messages, potentially leading to unauthorized tampering of business operations and abnormal system behavior. It is crucial for users of affected products to remain vigilant and implement appropriate security measures.

Affected Version(s)

DP300, RP200, TE30, TE40, TE50, TE60, eSpace U1981 V500R002C00

DP300, RP200, TE30, TE40, TE50, TE60, eSpace U1981 V500R002C00B010

DP300, RP200, TE30, TE40, TE50, TE60, eSpace U1981 V500R002C00B011

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.