CVE-2017-15352: Huawei Oceanstor 2800 Firmware

Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5500 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5600 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5800 V3, V300R003C00, V300R003C10, V300R003C20 have an improper access control vulnerability. Due to incorrectly restrict access to a resource, an attacker with high privilege may exploit the vulnerability to query some information or send specific message to cause some service abnormal.

Affected products

  • Huawei Oceanstor 2800 Firmware: version v300r003c00 only; version v300r003c20 only
  • Huawei Oceanstor 5300 Firmware: version v300r003c00 only; version v300r003c10 only; version v300r003c20 only
  • Huawei Oceanstor 5500 Firmware: version v300r003c00 only; version v300r003c10 only; version v300r003c20 only
  • Huawei Oceanstor 5600 Firmware: version v300r003c00 only; version v300r003c10 only; version v300r003c20 only
  • Huawei Oceanstor 5800 Firmware: version v300r003c00 only; version v300r003c10 only; version v300r003c20 only

Published 2018-02-15. Last modified 2026-06-17.