CVE-2016-6670

Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei_firmware:s12700:v200r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:s12700:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:huawei:s9700_firmware:v200r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:s9700_firmware:v200r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:s9700:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:huawei:s7700_firmware:v200r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:s7700_firmware:v200r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:s7700:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:huawei:s9300_firmware:v200r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:s9300_firmware:v200r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:s9300:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:56

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160810-01-certificate-en - Mitigation, Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160810-01-certificate-en - Mitigation, Vendor Advisory
References () http://www.securityfocus.com/bid/92438 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92438 - Third Party Advisory, VDB Entry

Information

Published : 2016-09-07 19:28

Updated : 2024-11-21 02:56


NVD link : CVE-2016-6670

Mitre link : CVE-2016-6670

CVE.ORG link : CVE-2016-6670


JSON object : View

Products Affected

huawei

  • s12700
  • s7700_firmware
  • s9700_firmware
  • s9300_firmware
  • s9700
  • s9300
  • s7700

huawei_firmware

  • s12700
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor