Este site utiliza cookies. Ao continuar navegando no site, você concorda com esse uso. Leia nossa política de privacidade
This security advisory (SA) describes the impact of DLL-Hijacking vulnerability discovered in website. (Vulnerability ID: HWPSIRT-2014-1046)
This vulnerability is referenced in this document as follows:
Any user in the system can modify the legitimate binary to any kind of malicious executable. If an attacker breakinto a low privilege account he could use this application to escalate his privileges.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8358.
The user could also place a malicious wintab32.dll file inside the "Mobile Partner" folder and perform DLL hijacking.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8359.
Product Name |
Affected Version |
Solved version |
EC177 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
EC176 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
EC156 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
CVE-2014-8358:
Base Score: 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Temporal Score: 5.0 (E:F/RL:O/RC:C)
Overall Score: 5.0
CVE-2014-8359:
Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Temporal Score: 5.0 (E:F/RL:O/RC:C)
Overall Score: 5.0For additional details, customers are advised to reference the website link:
http://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades, or obtain them through Huawei worldwide website at http://support.huawei.com/support/.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
None