7.5

CVE-2017-8174

Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and cause confidential information leaks on the transmission links.

Data is provided by the National Vulnerability Database (NVD)
HuaweiSecospace Usg6300 Firmware Versionv100r001c30spc300
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6600 Firmware Versionv100r001c30spc500
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv100r001c30spc600
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv100r001c30spc700
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv100r001c30spc800
   HuaweiSecospace Usg6600 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.209
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.