Attacker Value
Unknown
0
CVE-2017-14335
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Attacker Value
Unknown
(0 users assessed)Exploitability
Unknown
(0 users assessed)User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0
CVE-2017-14335
(Last updated November 26, 2024) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
n/a
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- 7204xr firmware -,
- 7208xr firmware -,
- 7216xr firmware -,
- hb7004k firmware -,
- hb7004kh firmware -,
- hb7008kc firmware -,
- hb7008kce firmware -,
- hb7008kh firmware -,
- hb7008khe firmware -,
- hb7008t2 firmware -,
- hb7016lc firmware -,
- hb7016lh firmware -,
- hb7016t2 firmware -,
- hb7024xt firmware -,
- hb7032xt firmware -,
- hb7108x3 firmware -,
- hb7116x3 firmware -,
- hb7204kk firmware -,
- hb7204kl firmware -,
- hb7204x firmware -,
- hb7204xt firmware -,
- hb7208x firmware -,
- hb7208x3 firmware -,
- hb7208xt firmware -,
- hb7216x firmware -,
- hb7216x3 firmware -,
- hb7216xt firmware -,
- hb7904 firmware -,
- hb7904x firmware -,
- hb7908 firmware -,
- hb7908x firmware -,
- hb7916s firmware -,
- hb7916sx firmware -,
- hb8004 firmware -,
- hb8004r firmware -,
- hb8008 firmware -,
- hb8008r firmware -,
- hb8016 firmware -,
- hb8016r firmware -,
- hb8204h firmware -,
- hb8204hr firmware -,
- hb8208h firmware -,
- hb8208hr firmware -,
- hb8208x3 firmware -,
- hb8216h firmware -,
- hb8216hr firmware -,
- hb8216x3 firmware -,
- hb8608x3 firmware -,
- hb8616x3 firmware -,
- hb8808x3 firmware -,
- hb8816x3 firmware -,
- hb9012x3 firmware -,
- hb9020x3 firmware -,
- hb9212x3 firmware -,
- hb9220x3 firmware -,
- hb9404x3 firmware -,
- hb9408x3 firmware -,
- hb9604x3 firmware -,
- hb9608x3 firmware -,
- hb9808n04 firmware -,
- hb9816n08 firmware -,
- hb9824n16 firmware -,
- hb9832n16 firmware -,
- hb9904 firmware -,
- hb9908 firmware -,
- hb9912 firmware -,
- hb9916 firmware -,
- hb9924 firmware -,
- hb9932 firmware -
References
Miscellaneous
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: