{"api_version":"1","generated_at":"2026-07-23T11:30:41+00:00","cve":"CVE-2017-15310","urls":{"html":"https://cve.report/CVE-2017-15310","api":"https://cve.report/api/cve/CVE-2017-15310.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15310","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15310"},"summary":{"title":"CVE-2017-15310","description":"Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.","state":"PUBLISHED","assigner":"huawei","published_at":"2017-12-22 17:29:13","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-20","arbitrary file deletion"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en","name":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory - Multiple Security Vulnerabilities in Huawei iReader","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15310","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15310","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Huawei Technologies Co., Ltd.","product":"iReader","version":"affected before 8.0.2.301","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15310","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"huawei","cpe5":"ireader","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"15310","cve":"CVE-2017-15310","epss":"0.001230000","percentile":"0.309030000","score_date":"2026-05-19","updated_at":"2026-05-20 00:11:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:50:16.496Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"iReader","vendor":"Huawei Technologies Co., Ltd.","versions":[{"status":"affected","version":"before 8.0.2.301"}]}],"datePublic":"2017-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card."}],"problemTypes":[{"descriptions":[{"description":"arbitrary file deletion","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-22T16:57:01.000Z","orgId":"25ac1063-e409-4190-8079-24548c77ea2e","shortName":"huawei"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@huawei.com","DATE_PUBLIC":"2017-11-20T00:00:00","ID":"CVE-2017-15310","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"iReader","version":{"version_data":[{"version_value":"before 8.0.2.301"}]}}]},"vendor_name":"Huawei Technologies Co., Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"arbitrary file deletion"}]}]},"references":{"reference_data":[{"name":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en","refsource":"CONFIRM","url":"http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171120-01-hwreader-en"}]}}}},"cveMetadata":{"assignerOrgId":"25ac1063-e409-4190-8079-24548c77ea2e","assignerShortName":"huawei","cveId":"CVE-2017-15310","datePublished":"2017-12-22T17:00:00.000Z","dateReserved":"2017-10-14T00:00:00.000Z","dateUpdated":"2024-09-16T20:21:46.076Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-22 17:29:13","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-20","arbitrary file deletion"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:huawei:ireader:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.2.301","matchCriteriaId":"F2028F4E-4042-40E1-9A67-84D18B5EED35"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15310","Ordinal":"1","Title":"CVE-2017-15310","CVE":"CVE-2017-15310","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15310","Ordinal":"1","NoteData":"Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.","Type":"Description","Title":"CVE-2017-15310"},{"CveYear":"2017","CveId":"15310","Ordinal":"2","NoteData":"2017-12-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15310","Ordinal":"3","NoteData":"2017-12-22","Type":"Other","Title":"Modified"}]}}}