CVE-2017-17221
Estado: ModificadaAlta (8.8)—
Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.25%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-17221",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "Huawei Technologies Co., Ltd.",
"product": "eSpace 7950; eSpace 8950",
"versions": [
{
"status": "affected",
"version": "eSpace 7950 V200R003C30"
},
{
"status": "affected",
"version": "eSpace 8950 V200R003C00"
},
{
"status": "affected",
"version": "V200R003C30"
}
]
}
]
}
],
"published": "2018-03-09T17:29:01.250",
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-01-espace-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-01-espace-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code."
},
{
"lang": "es",
"value": "La función Import Signal Tone en Huawei eSpace 7950 V200R003C30 y eSpace 8950 V200R003C00 y V200R003C30 tiene una vulnerabilidad de ejecución remota de código. Un atacante remoto autenticado puede manipular y enviar los paquetes a los productos afectados una vez se haya subido el Signal Tone. Dada la verificación insuficiente de los paquetes, esto podría explotarse para ejecutar código arbitrario."
}
],
"lastModified": "2026-06-17T01:10:32.737",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:espace_7950_firmware:v200r003c30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4523A712-FF77-4BDA-B213-0AE2BDC4152C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:espace_7950:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "185783AE-3135-471E-8D55-4BAB3A187F21"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:espace_8950_firmware:v200r003c00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72548F60-D6B8-4498-8668-9074A706C3A7"
},
{
"criteria": "cpe:2.3:o:huawei:espace_8950_firmware:v200r003c30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E0B1E39-ACEB-44FB-BDDE-F3856CF6137A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:espace_8950:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8BFC4FD-DC7A-47E9-BC06-86F11E2211AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}