Show plain JSON{"id": "CVE-2017-15321", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.2}]}, "published": "2017-12-22T17:29:13.393", "references": [{"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171108-01-fusionsphere-en", "tags": ["Vendor Advisory"], "source": "psirt@huawei.com"}, {"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171108-01-fusionsphere-en", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target device. Successful exploit could cause an information leak."}, {"lang": "es", "value": "Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) contiene una vulnerabilidad de fuga de informaci\u00f3n debida al uso de un protocolo de transmisi\u00f3n en versiones antiguas por defecto. Un atacante podr\u00eda interceptar paquetes transferidos por un dispositivo objetivo. Una explotaci\u00f3n exitosa pod\u00eda provocar una fuga de informaci\u00f3n."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:huawei:fusionsphere_openstack:v100r006c000spc102_\\(nfv\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A988CAC-A3EA-4CD3-80F9-9AAE28464102"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@huawei.com"}