PT-2013-2025 · Huawei · Huawei Bims+8

Felix Lindner

·

Publicado

2013-06-20

·

Atualizado

2013-09-02

·

CVE-2012-6571

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Huawei BIMS and web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches (affected versions not specified)
Description The issue concerns the HTTP module in the affected systems, which generates predictable Session ID values. This predictability makes it easier for remote attackers to hijack sessions using a brute-force attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-6571

Produtos afetados

Huawei Ar Routers
Huawei Bims
S2000
S3000
S3500
S3900
S5100
S5600
S7800