Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2271

Опубликовано: 14 янв. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wps:wps_office:5.3.1:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:huawei:p2-6011_firmware:*:*:*:*:*:*:*:*
Версия до v100r001c00b043 (исключая)
cpe:2.3:h:huawei:p2-6011:-:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01795
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.

EPSS

Процентиль: 82%
0.01795
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20