CVE-2017-17305
Last modified
CVE-2017-17305 is a vulnerability of currently unknown severity. Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by leveraging a Bleichenbacher RSA padding oracle. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by leveraging a Bleichenbacher RSA padding oracle. Cause a Bleichenbacher oracle attack. Successful exploit this vulnerability can impact IPSec tunnel security.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Usg2205bsr Firmware | v300r001c10spc600 |
| Huawei | Usg2220bsr Firmware | v300r001c00 |
| Huawei | Usg5120bsr Firmware | v300r001c00 |
| Huawei | Usg5150bsr Firmware | v300r001c00 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17305?
How severe is CVE-2017-17305?
How do I fix CVE-2017-17305?
Are you affected by CVE-2017-17305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
