cve-2017-17215

HIGH CVSS 8.8 opencve
Description

Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.

Timeline
Published
2018-03-20 15:29 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.0 8.8 HIGH CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H nvd
3.0 8.8 HIGH CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2017-17215",
  "epss": {
    "score": 0.78278
  },
  "mitre": {
    "cpes": [],
    "created": "2018-03-20T15:00:00+00:00",
    "description": "Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2017/17xxx/CVE-2017-17215.json",
    "references": [
      "http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en",
      "http://www.securityfocus.com/bid/102344"
    ],
    "title": null,
    "updated": "2024-08-05T20:43:59.888000+00:00",
    "vendors": [],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:h:huawei:hg532:-:*:*:*:*:*:*:*",
      "cpe:2.3:o:huawei:hg532_firmware:-:*:*:*:*:*:*:*"
    ],
    "created": "2018-03-20T15:29:00.203000+00:00",
    "description": "Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.",
    "metrics": {
      "cvssV2_0": {
        "score": 6.5,
        "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
      },
      "cvssV3_0": {
        "score": 8.8,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2017/CVE-2017-17215.json",
    "references": [
      "http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en",
      "http://www.securityfocus.com/bid/102344"
    ],
    "title": null,
    "updated": "2026-06-17T01:10:32.077000+00:00",
    "vendors": [
      "huawei",
      "huawei$PRODUCT$hg532",
      "huawei$PRODUCT$hg532_firmware"
    ],
    "weaknesses": [
      "CWE-20"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-07-16T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.92098
                  },
                  "old": {
                    "score": 0.92051
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "71f2e363-7168-4db6-8804-cde81671d88d"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:h:huawei:hg532:-:*:*:*:*:*:*:*",
        "cpe:2.3:o:huawei:hg532_firmware:-:*:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2018-03-20T15:00:00+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {
          "score": 6.5,
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
        },
        "provider": "nvd"
      },
      "cvssV3_0": {
        "data": {
          "score": 8.8,
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "nvd"
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.78278
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {},
        "provider": null
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en",
        "http://www.securityfocus.com/bid/102344"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2024-11-21T03:17:40.740000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "huawei",
        "huawei$PRODUCT$hg532",
        "huawei$PRODUCT$hg532_firmware"
      ],
      "providers": [
        "nvd"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-20"
      ],
      "providers": [
        "nvd"
      ]
    }
  }
}
View JSON API Download JSON