CVE-2017-17223
Summary
| CVE | CVE-2017-17223 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-09 17:29:00 UTC |
| Updated | 2018-03-26 17:26:00 UTC |
| Description | Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful exploit will upload and download files and cause information leak and system crash. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Espace 7910 | - | All | All | All |
| Hardware | Huawei | Espace 7910 | - | All | All | All |
| Operating System | Huawei | Espace 7910 Firmware | v200r003c30 | All | All | All |
| Operating System | Huawei | Espace 7910 Firmware | v200r003c30 | All | All | All |
| Hardware | Huawei | Espace 7950 | - | All | All | All |
| Hardware | Huawei | Espace 7950 | - | All | All | All |
| Operating System | Huawei | Espace 7950 Firmware | v200r003c30 | All | All | All |
| Operating System | Huawei | Espace 7950 Firmware | v200r003c30 | All | All | All |
| Hardware | Huawei | Espace 8950 | - | All | All | All |
| Hardware | Huawei | Espace 8950 | - | All | All | All |
| Operating System | Huawei | Espace 8950 Firmware | v200r003c00 | All | All | All |
| Operating System | Huawei | Espace 8950 Firmware | v200r003c30 | All | All | All |
| Operating System | Huawei | Espace 8950 Firmware | v200r003c00 | All | All | All |
| Operating System | Huawei | Espace 8950 Firmware | v200r003c30 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Directory Traversal Vulnerability in Huawei eSpace Product | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.