This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy

Security Notice - Statement about the OpenSSL Certificate Verification Vulnerability

  • Initial Release Date: 2015-07-10
  • Last Release Date: 2015-09-19

Huawei noticed that a certificate verification bypass vulnerability (CVE-2015-1793) was disclosed in specific OpenSSL versions on July 9, 2015. Huawei has started an investigation immediately after learning about the vulnerability.

The investigation has been completed, it has been verified that Huawei eSight Network has security vulnerability that could be exploited by attackers who can intercept the communication data between the two communication parties.

Huawei has delivered Security Advisories and mitigation measures. Customers can get necessary support for product security vulnerabilities through Huawei local technical service. The link of the security advisory is:

http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-454058.htm

2015-09-19 FINAL

2015-07-10 INITIAL

Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism. Please report to Huawei PSIRT at psirt@huawei.com if you find any security vulnerability of Huawei products.