CVE-2017-17303 describes an information disclosure vulnerability in multiple Huawei DP300, RP200, TE30, TE40, TE50, and TE60 products. These devices, when using the CIDAM protocol, expose sensitive information within messages. An authenticated remote attacker could exploit this to track and intercept messages, leading to the disclosure of sensitive data. The vulnerability has a CVSS v3.0 score of 4.9 (Medium), indicating a network attack vector with low attack complexity, requiring high privileges, and resulting in high confidentiality impact without affecting integrity or availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v500r002c00CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00:*:*:*:*:*:*:* | ||
v500r002c00b010CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00b010:*:*:*:*:*:*:* | ||
v500r002c00b011CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00b011:*:*:*:*:*:*:* | ||
v500r002c00b012CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00b012:*:*:*:*:*:*:* | ||
v500r002c00b013CPE matchmatch criteria | cpe:2.3:o:huawei:dp300_firmware:v500r002c00b013:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.