Bleichenbacher Oracle Vulnerability in Huawei Firewall Products
CVE-2017-17305

5.9MEDIUM

Key Information:

Vendor

McAfee

Vendor
CVE Published:
21 August 2018

What is CVE-2017-17305?

Certain Huawei Firewall products are susceptible to a security flaw in their IPSEC IKEv1 implementations, known as a Bleichenbacher Oracle vulnerability. This issue allows remote attackers to exploit the RSA padding oracle, enabling them to decrypt IPSEC tunnel ciphertext data. Such an attack could compromise the integrity of the IPSEC tunnel, posing significant risks to network security.

Affected Version(s)

USG2205BSR; USG2220BSR; USG5120BSR; USG5150BSR USG2205BSR V300R001C10SPC600

USG2205BSR; USG2220BSR; USG5120BSR; USG5150BSR USG2220BSR V300R001C00

USG2205BSR; USG2220BSR; USG5120BSR; USG5150BSR USG5120BSR V300R001C00

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.