« Volver al listado

CVE-2017-8176

Estado: ModificadaAlta (7.5)—

Huawei IPTV STB, con versiones anteriores a IPTV STB V100R003C01LMYTa6SPC001, tiene una vulnerabilidad de omisión de autenticación. Un atacante podría explotar esta vulnerabilidad para acceder a la interfaz serie y modificar la configuración. Si se explota con éxito, podría desembocar en una omisión de autenticación y en la visión de canales gratuitamente.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-8176",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei Technologies Co., Ltd.",
          "product": "IPTV STB",
          "versions": [
            {
              "status": "affected",
              "version": "Earlier than IPTV STB V100R003C01LMYTa6SPC001 versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-20T15:29:00.533",
  "references": [
    {
      "url": "http://security.my/post/165370836947/cve-2017-8176",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://support.huawei.com/carrier/navi?coltype=software?lang=en#col=software&detailId=PBI1-22570793&path=PBI1-21262245/PBI1-22317450/PBI1-22317491/PBI1-19974608/PBI1-14715&lang=en%3B",
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://security.my/post/165370836947/cve-2017-8176",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.huawei.com/carrier/navi?coltype=software?lang=en#col=software&detailId=PBI1-22570793&path=PBI1-21262245/PBI1-22317450/PBI1-22317491/PBI1-19974608/PBI1-14715&lang=en%3B",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Huawei IPTV STB with earlier than IPTV STB V100R003C01LMYTa6SPC001 versions has an authentication bypass vulnerability. An attacker could exploit this vulnerability to access the serial interface and modify the configuration. Successful exploit could lead to the authentication bypass and view channels by free."
    },
    {
      "lang": "es",
      "value": "Huawei IPTV STB, con versiones anteriores a IPTV STB V100R003C01LMYTa6SPC001, tiene una vulnerabilidad de omisión de autenticación. Un atacante podría explotar esta vulnerabilidad para acceder a la interfaz serie y modificar la configuración. Si se explota con éxito, podría desembocar en una omisión de autenticación y en la visión de canales gratuitamente."
    }
  ],
  "lastModified": "2026-06-17T01:25:55.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:iptv_stb_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5235F6C-40BC-40FD-947C-16B0ECA74D39",
              "versionEndExcluding": "v100r003c01lmyta6spc001"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:iptv_stb:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC278E31-C7CA-40C9-A6C9-64112505993F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}