Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.108797
Kategorie:Huawei
Titel:Huawei Data Communication: Improper Authentication Vulnerability in Some Huawei CloudEngine Products (huawei-sa-20190918-01-authentication)
Zusammenfassung:There is an improper authentication vulnerability in some Huawei CloudEngine products.
Beschreibung:Summary:
There is an improper authentication vulnerability in some Huawei CloudEngine products.

Vulnerability Insight:
There is an improper authentication vulnerability in some Huawei CloudEngine products. Due to the improper implementation of authentication for the serial port, an attacker could exploit this vulnerability by connecting to the affected products and run a series of commands. (Vulnerability ID: HWPSIRT-2019-06031)This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-5304.Huawei has released software updates to fix this vulnerability. This advisory is available in the linked references.

Vulnerability Impact:
An attacker could exploit this vulnerability by connecting to the affected products and run a series of commands.

Affected Software/OS:
CloudEngine 12800 versions V200R003C00SPC810 V200R005C00SPC600 V200R005C00SPC800PWE V200R005C10

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-5304
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200102-01-buffer-en
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.