CVE-2017-2704

Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and earlier versions,HwCloudDrive(EMUI6.0) 8.0.0.307 and earlier versions,HwPhoneFinder(EMUI6.0) 9.3.0.310 and earlier versions,HwPhoneFinder(EMUI5.1) 9.2.2.303 and earlier versions,HiCinema 8.0.2.300 and earlier versions,HuaweiWear 21.0.0.360 and earlier versions,HiHealthApp 3.0.3.300 and earlier versions have an information exposure vulnerability. Encryption keys are stored in the system. The attacker can implement reverse engineering to obtain the encryption keys, causing information exposure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
huaweiCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
huaweismarthome
𝑥
≤ 1.0.2.364
huaweihiapp
𝑥
≤ 7.3.0.303
huaweihwparentcontrol
𝑥
≤ 2.0.0
huaweihwparentcontrolparent
𝑥
≤ 5.1.0.12
huaweicrowdtest
𝑥
≤ 1.5.3
huaweihiwallet
𝑥
≤ 8.0.0.301
huaweihuawei_pay
𝑥
≤ 8.0.0.300
huaweiskytone
𝑥
≤ 8.1.2.300
huaweihwclouddrive\(emui6.0\)
𝑥
≤ 8.0.0.307
huaweihwphonefinder\(emui6.0\)
𝑥
≤ 9.3.0.310
huaweihwphonefinder\(emui5.1\)
𝑥
≤ 9.2.2.303
huaweihicinema
𝑥
≤ 8.0.2.300
huaweihuaweiwear
𝑥
≤ 21.0.0.360
huaweihihealthapp
𝑥
≤ 3.0.3.300
𝑥
= Vulnerable software versions