CVE-2017-17223
HIGHHuawei eSpace 7910 7950 8950 Firmware - Authenticated Path Traversal
Title source: llmDescription
Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful exploit will upload and download files and cause information leak and system crash.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-02-espace-en
Scores
CVSS v3
8.8
EPSS
0.0061
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (4)
huawei/espace_7910_firmware
v200r003c30
huawei/espace_7950_firmware
v200r003c30
huawei/espace_8950_firmware
v200r003c00
huawei/espace_8950_firmware
v200r003c30
Published
Mar 09, 2018
Tracked Since
Feb 18, 2026