CVE-2017-8213
Last modified
CVE-2017-8213 is a vulnerability of currently unknown severity. Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote attackers could exploit this vulnerability to crash the TLS module.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote attackers could exploit this vulnerability to crash the TLS module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Smc2.0 Firmware | v100r003c10 |
| Huawei | Smc2.0 Firmware | v100r005c00spc100 |
| Huawei | Smc2.0 Firmware | v100r005c00spc101b001t |
| Huawei | Smc2.0 Firmware | v100r005c00spc102 |
| Huawei | Smc2.0 Firmware | v100r005c00spc103 |
| Huawei | Smc2.0 Firmware | v100r005c00spc200 |
| Huawei | Smc2.0 Firmware | v100r005c00spc201t |
| Huawei | Smc2.0 Firmware | v500r002c00 |
| Huawei | Smc2.0 Firmware | v600r006c00 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8213?
How severe is CVE-2017-8213?
How do I fix CVE-2017-8213?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8207The driver of honor 5C, honor 6x Huawei smart phones with so…
- CVE-2017-8208The driver of honor 5C,honor 6x Huawei smart phones with sof…
- CVE-2017-8209The driver of honor 5C,honor 6x Huawei smart phones with sof…
- CVE-2017-8210The driver of honor 5C,honor 6x Huawei smart phones with sof…
- CVE-2017-8211The driver of honor 5C,honor 6x Huawei smart phones with sof…
- CVE-2017-8212The driver of honor 5C,honor 6x Huawei smart phones with sof…
- CVE-2017-8214Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 …
- CVE-2017-8215Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 …
- CVE-2017-8216Warsaw Huawei Smart phones with software of versions earlier…
- CVE-2017-8217TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032…
- CVE-2017-8218vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1…
- CVE-2017-8219TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032…
Are you affected by CVE-2017-8213?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
