SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-15326

DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability.

MEDIUM 4.3EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an insecure encryption algorithm is negotiated in the communication, an unauthenticated remote attacker can exploit this vulnerability to crack the encrypted data and cause information leakage.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-327
Affected
huawei/dbs3900 tdd lte firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.