CVE-2016-6670
MEDIUMHuawei Firmware S12700 - Information Disclosure
Title source: ruleDescription
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
Scores
CVSS v3
5.3
EPSS
0.0010
EPSS Percentile
28.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (8)
huawei_firmware/s12700
huawei/s9700_firmware
huawei/s9700_firmware
huawei/s7700_firmware
huawei/s7700_firmware
huawei/s9300_firmware
huawei/s9300_firmware
n/a/n/a
Timeline
Published
Sep 07, 2016
Tracked Since
Feb 18, 2026