CVE-2017-17302 describes a memory leak vulnerability affecting various Huawei DP300, RP200, and TE series video conferencing products. An authenticated, local attacker can repeatedly load specially crafted Certificate Revocation List (CRL) configuration files, causing the device to improperly release allocated memory. This can lead to a memory leak and service instability. The vulnerability has a CVSS v3.0 score of 3.3 (LOW), indicating a local attack vector with low complexity and requiring low privileges, resulting in a low impact on availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v500r002c00CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00:*:*:*:*:*:*:* | ||
v600r006c00CPE matchmatch criteria | cpe:2.3:o:huawei:rp200_firmware:v600r006c00:*:*:*:*:*:*:* | ||
v100r001c10CPE matchmatch criteria | cpe:2.3:o:huawei:te30_firmware:v100r001c10:*:*:*:*:*:*:* | ||
v500r002c00CPE matchmatch criteria | cpe:2.3:o:huawei:te30_firmware:v500r002c00:*:*:*:*:*:*:* | ||
v600r006c00CPE matchmatch criteria | cpe:2.3:o:huawei:te30_firmware:v600r006c00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.