CVE-2017-2704

Published: Nov 22, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-11847 Aliases: GSD-2017-2704
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and earlier versions,HwCloudDrive(EMUI6.0) 8.0.0.307 and earlier versions,HwPhoneFinder(EMUI6.0) 9.3.0.310 and earlier versions,HwPhoneFinder(EMUI5.1) 9.2.2.303 and earlier versions,HiCinema 8.0.2.300 and earlier versions,HuaweiWear 21.0.0.360 and earlier versions,HiHealthApp 3.0.3.300 and earlier versions have an information exposure vulnerability. Encryption keys are stored in the system. The attacker can implement reverse engineering to obtain the encryption keys, causing information exposure.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0008
Percentile
0,2th
Updated

EPSS Score Trend (Last 90 Days)

200

Exposure of Sensitive Information to an Unauthorized Actor

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies: Mobile, Not Technology-Specific, Web Based
View CWE Details
Application

Huaweiwear by Huawei

Version Range Affected
To 21.0.0.360 (inclusive)
cpe:2.3:a:huawei:huaweiwear:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hihealthapp by Huawei

Version Range Affected
To 3.0.3.300 (inclusive)
cpe:2.3:a:huawei:hihealthapp:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hiapp by Huawei

Version Range Affected
To 7.3.0.303 (inclusive)
cpe:2.3:a:huawei:hiapp:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hicinema by Huawei

Version Range Affected
To 8.0.2.300 (inclusive)
cpe:2.3:a:huawei:hicinema:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hwphonefinder\(Emui5.1\) by Huawei

Version Range Affected
To 9.2.2.303 (inclusive)
cpe:2.3:a:huawei:hwphonefinder\(emui5.1\):*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hwphonefinder\(Emui6.0\) by Huawei

Version Range Affected
To 9.3.0.310 (inclusive)
cpe:2.3:a:huawei:hwphonefinder\(emui6.0\):*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Hwclouddrive\(Emui6.0\) by Huawei

Version Range Affected
To 8.0.0.307 (inclusive)
cpe:2.3:o:huawei:hwclouddrive\(emui6.0\):*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Huawei Pay by Huawei

Version Range Affected
To 8.0.0.300 (inclusive)
cpe:2.3:a:huawei:huawei_pay:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hwparentcontrolparent by Huawei

Version Range Affected
To 5.1.0.12 (inclusive)
cpe:2.3:a:huawei:hwparentcontrolparent:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Skytone by Huawei

Version Range Affected
To 8.1.2.300 (inclusive)
cpe:2.3:a:huawei:skytone:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hwparentcontrol by Huawei

Version Range Affected
To 2.0.0 (inclusive)
cpe:2.3:a:huawei:hwparentcontrol:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Hiwallet by Huawei

Version Range Affected
To 8.0.0.301 (inclusive)
cpe:2.3:a:huawei:hiwallet:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Crowdtest by Huawei

Version Range Affected
To 1.5.3 (inclusive)
cpe:2.3:a:huawei:crowdtest:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Smarthome by Huawei

Version Range Affected
To 1.0.2.364 (inclusive)
cpe:2.3:a:huawei:smarthome:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-encryp…
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170920-01-encryp…