CVE-2014-2271

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/01/2020
Last modified:
21/01/2020

Description

cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wps:wps_office:5.3.1:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p2-6011_firmware:*:*:*:*:*:*:*:* v100r001c00b043 (excluding)
cpe:2.3:h:huawei:p2-6011:-:*:*:*:*:*:*:*