Security Advisory - Three OpenSSL Vulnerabilities in Huawei Products

Related Vulnerabilities: CVE-2017-3730   CVE-2017-3731   CVE-2017-3732   CVE-2017-3730   CVE-2017-3731   CVE-2017-3732  

On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities.  If a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. (Vulnerability ID: HWPSIRT-2017-02005)  This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3730.  If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. (Vulnerability ID: HWPSIRT-2017-02006)  This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3731.  There is a vulnerability in the x86_64 Montgomery squaring procedure, if DH parameters are used and a private key is shared between multiple clients, a successful exploit could allow the attacker to access sensitive private key information. (Vulnerability ID: HWPSIRT-2017-02007)   This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3732. Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:  http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170503-01-openssl-en

Buy

Security Advisory - Three OpenSSL Vulnerabilities in Huawei Products

  • SA No:huawei-sa-20170503-01-openssl
  • Initial Release Date: May 03, 2017
  • Last Release Date: Jan 15, 2020

On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. 
If a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. (Vulnerability ID: HWPSIRT-2017-02005) 
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3730. 
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. (Vulnerability ID: HWPSIRT-2017-02006) 
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3731. 
There is a vulnerability in the x86_64 Montgomery squaring procedure, if DH parameters are used and a private key is shared between multiple clients, a successful exploit could allow the attacker to access sensitive private key information. (Vulnerability ID: HWPSIRT-2017-02007)  
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3732.

Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link: 

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170503-01-openssl-en

Product Name

Affected Version

Resolved Product and Version

AC6005

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC300PWE

V200R007C10SPH201

V200R007C10SPH301

V200R007C10SPH301PWE

AC6605

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC300PWE

V200R007C10SPH201

V200R007C10SPH301

V200R007C10SPH301PWE

AP2000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP3000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP4000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP6000

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP7000

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

IPS Module

V500R001C30

Upgrade to V5R5C00SPC100

V500R001C50

V500R001C50PWE

NGFW Module

V500R002C00

Upgrade to V5R5C00SPC100

V500R002C10

V500R002C10PWE

OceanStor 9000

V300R005C00

Upgrade to V300R006C00SPC100

OceanStor Backup Software

V200R001C00

OceanStor BCManager V200R001C00SPC203

RH5885 V3

V100R003C01

V100R003C01SPC121

V100R003C10

V100R003C10SPC111

Secospace AntiDDoS8000

V500R001C60SPC501

Upgrade to V500R005C00SPC300

V500R001C60SPC600

V500R001C60SPH601

V500R005C00SPC100

V500R005C00SPC300

Secospace AntiDDoS8030

V500R001C60SPC100

Upgrade to V500R005C00

V500R001C60SPC300

V500R001C60SPC500

V500R001C80

Secospace USG6600

V500R001C30

V500R001C30SPC600

V500R001C50

V500R001C50PWE

UPS2000

V100R002C02

V100R002C02SPC302

V200R001C31

V200R001C01SPC300

V200R001C90

V100R002C02SPC302

USG9500

V500R001C30SPC100

V500R001C30SPC600

V500R001C30SPC200

eSpace VCN3000

V100R002C10SPC103

Upgrade to V100R002C30

V100R002C20SPC207



HWPSIRT-2017-02005:

A successful exploit may cause OpenSSL to crash when connecting to a malicious server.

HWPSIRT-2017-02006:

A successful exploit may cause OpenSSL to crash.

HWPSIRT-2017-02007:

A successful exploit could allow the attacker to access sensitive private key information.

The vulnerability classification has been performed by using the CVSSv3 scoring system (http://www.first.org/cvss/specification-document).

HWPSIRT-2017-02005:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

HWPSIRT-2017-02006:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

HWPSIRT-2017-02007:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

Vulnerability details:

For technical details, customers are advised to reference the website: https://www.openssl.org/news/secadv/20170126.txt

Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades. For TAC contact information, please refer to Huawei worldwide website at http://www.huawei.com/en/psirt/report-vulnerabilities.

These vulnerabilities were disclosed by OpenSSL official website.

2020-01-15 V1.2 UPDATED Updated the "Software Versions and Fixes" section;

2017-11-29 V1.1 UPDATED Updated the "Software Versions and Fixes" section;

2017-05-03 V1.0 INITIAL


Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism.

To enjoy Huawei PSIRT services and obtain Huawei product vulnerability information, please visit http://www.huawei.com/en/psirt.

To report a security vulnerability in Huawei products and solutions, please send it to PSIRT@huawei.com. For details, please visit http://www.huawei.com/en/psirt/report-vulnerabilities.

This document is provided on an "AS IS" basis and does not imply any kind of guarantee or warranty, either express or implied, including the warranties of merchantability or fitness for a particular purpose. In no event shall Huawei or any of its directly or indirectly controlled subsidiaries or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. Your use of the document, by whatsoever means, will be totally at your own risk. Huawei is entitled to amend or update this document from time to time.

Security Advisory - Three OpenSSL Vulnerabilities in Huawei Products

  • SA No:huawei-sa-20170503-01-openssl
  • Initial Release Date: May 03, 2017
  • Last Release Date: Jan 15, 2020

On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. 
If a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. (Vulnerability ID: HWPSIRT-2017-02005) 
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3730. 
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. (Vulnerability ID: HWPSIRT-2017-02006) 
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3731. 
There is a vulnerability in the x86_64 Montgomery squaring procedure, if DH parameters are used and a private key is shared between multiple clients, a successful exploit could allow the attacker to access sensitive private key information. (Vulnerability ID: HWPSIRT-2017-02007)  
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-3732.

Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link: 

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170503-01-openssl-en

Product Name

Affected Version

Resolved Product and Version

AC6005

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC300PWE

V200R007C10SPH201

V200R007C10SPH301

V200R007C10SPH301PWE

AC6605

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC300PWE

V200R007C10SPH201

V200R007C10SPH301

V200R007C10SPH301PWE

AP2000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP3000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP4000

V200R007C10SPC200

Upgrade to V200R007C20SPC200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP6000

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

AP7000

V200R007C10SPC200

Upgrade to v200r007c20spc200

V200R007C10SPC300

V200R007C10SPC500

V200R007C10SPC600

IPS Module

V500R001C30

Upgrade to V5R5C00SPC100

V500R001C50

V500R001C50PWE

NGFW Module

V500R002C00

Upgrade to V5R5C00SPC100

V500R002C10

V500R002C10PWE

OceanStor 9000

V300R005C00

Upgrade to V300R006C00SPC100

OceanStor Backup Software

V200R001C00

OceanStor BCManager V200R001C00SPC203

RH5885 V3

V100R003C01

V100R003C01SPC121

V100R003C10

V100R003C10SPC111

Secospace AntiDDoS8000

V500R001C60SPC501

Upgrade to V500R005C00SPC300

V500R001C60SPC600

V500R001C60SPH601

V500R005C00SPC100

V500R005C00SPC300

Secospace AntiDDoS8030

V500R001C60SPC100

Upgrade to V500R005C00

V500R001C60SPC300

V500R001C60SPC500

V500R001C80

Secospace USG6600

V500R001C30

V500R001C30SPC600

V500R001C50

V500R001C50PWE

UPS2000

V100R002C02

V100R002C02SPC302

V200R001C31

V200R001C01SPC300

V200R001C90

V100R002C02SPC302

USG9500

V500R001C30SPC100

V500R001C30SPC600

V500R001C30SPC200

eSpace VCN3000

V100R002C10SPC103

Upgrade to V100R002C30

V100R002C20SPC207



HWPSIRT-2017-02005:

A successful exploit may cause OpenSSL to crash when connecting to a malicious server.

HWPSIRT-2017-02006:

A successful exploit may cause OpenSSL to crash.

HWPSIRT-2017-02007:

A successful exploit could allow the attacker to access sensitive private key information.

The vulnerability classification has been performed by using the CVSSv3 scoring system (http://www.first.org/cvss/specification-document).

HWPSIRT-2017-02005:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

HWPSIRT-2017-02006:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

HWPSIRT-2017-02007:

Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Temporal Score: 5.5 (E:F/RL:O/RC:C)

Vulnerability details:

For technical details, customers are advised to reference the website: https://www.openssl.org/news/secadv/20170126.txt

Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades. For TAC contact information, please refer to Huawei worldwide website at http://www.huawei.com/en/psirt/report-vulnerabilities.

These vulnerabilities were disclosed by OpenSSL official website.

2020-01-15 V1.2 UPDATED Updated the "Software Versions and Fixes" section;

2017-11-29 V1.1 UPDATED Updated the "Software Versions and Fixes" section;

2017-05-03 V1.0 INITIAL


Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism.

To enjoy Huawei PSIRT services and obtain Huawei product vulnerability information, please visit http://www.huawei.com/en/psirt.

To report a security vulnerability in Huawei products and solutions, please send it to PSIRT@huawei.com. For details, please visit http://www.huawei.com/en/psirt/report-vulnerabilities.

This document is provided on an "AS IS" basis and does not imply any kind of guarantee or warranty, either express or implied, including the warranties of merchantability or fitness for a particular purpose. In no event shall Huawei or any of its directly or indirectly controlled subsidiaries or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. Your use of the document, by whatsoever means, will be totally at your own risk. Huawei is entitled to amend or update this document from time to time.