CVE-2014-9690
CVSS V2 Medium 5
CVSS V3 High 7.5
Description
Huawei home gateways WS318 with software V100R001C01B022 and earlier versions are affected by the PIN offline brute force cracking vulnerability of the WPS protocol because the random number generator (RNG) used in the supplier's solution is not random enough. As a result, brute force cracking the PIN code is easier. After an attacker cracks the PIN, the attacker can access the Internet via the cracked device.
Overview
- CVE ID
- CVE-2014-9690
- Assigner
- psirt@huawei.com
- Vulnerability Status
- Analyzed
- Published Version
- 2017-04-02T20:59:00
- Last Modified Date
- 2017-04-05T18:32:58
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:o:huawei:ws318_firmware:*:*:*:*:*:*:*:* | 1 | OR | v100r001c01b022 | |
cpe:2.3:h:huawei:ws318:-:*:*:*:*:*:*:* | 0 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 5
- Severity
- MEDIUM
- Exploitability Score
- 10
- Impact Score
- 2.9
CVSS Version 3
- Version
- 3.0
- Vector String
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 7.5
- Base Severity
- HIGH
- Exploitability Score
- 3.9
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
http://www.huawei.com/en/psirt/security-advisories/hw-408091 | Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2014-9690 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9690 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 09:45:47 | Added to TrackCVE | |||
2022-12-02 15:24:24 | 2017-04-02T20:59Z | 2017-04-02T20:59:00 | CVE Published Date | updated |
2022-12-02 15:24:24 | 2017-04-05T18:32:58 | CVE Modified Date | updated | |
2022-12-02 15:24:24 | Analyzed | Vulnerability Status | updated |