Vulnerability Details CVE-2014-2271
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 82.0%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2014-2271
-
cpe:2.3:a:wps:wps_office:5.3.1
-
cpe:2.3:h:huawei:p2-6011:-
-
cpe:2.3:o:huawei:p2-6011_firmware:-
-
cpe:2.3:o:huawei:p2-6011_firmware:v100r001c00b042