Este site utiliza cookies. Ao continuar navegando no site, você concorda com esse uso. Leia nossa política de privacidade
Security Advisory - Plaintext User Password Vulnerability in VCN500 Logs
- SA No:SA No: Huawei-SA-20151126-04-VCN500
- Initial Release Date:2015-11-26
- Last Release Date:2015-11-26
Huawei VCN500 (Video Cloud Node) logs user passwords in plaintext for specific operations on the certain interface, leading to user password leakage. (Vulnerability ID:HWPSIRT-2015-09032)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8335.
Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-463084.htm
|
Product Name |
Affected Version |
Resolved Product and Version |
|
VCN500 |
V100R002C00SPC200B010 |
V100R002C00SPC201 |
|
V100R002C00SPC200 |
An attacker may exploit this vulnerability to obtain user passwords.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Temporal Score: 5.0 (E:F/RL:O/RC:C)1. Prerequisites:
1) The attacker logs in to VCN500 as an authorized user and obtains logs.
2) The attacker knows how to trigger log generation.
2. Attacking procedure:
The attacker sends specially crafted packets to trigger log generation.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2015-11-26 V1.0 INITIAL
None