PT-2014-6067 · Huawei · Huawei Campus S7700+3
Publicado
2014-05-07
·
Atualizado
2017-04-06
·
CVE-2014-4707
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300
Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300
Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300
Description
The issue allows unauthorized users to upgrade the bootrom or bootload software, bypass a Menu protection mechanism, conduct a Menu compromise attack, or bypass a Menu/upgrade protection mechanism. This can be achieved through the BootRom and Boot Menu vulnerability, which enables unauthorized users to bypass the system security check mechanism and compromise the switch.
Recommendations
For Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300, restrict access to the bootrom and bootload software upgrade functionality until a patch is available.
For Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300, consider disabling the Boot Menu to prevent unauthorized upgrades and bypassing of the system security check mechanism.
For Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300, avoid using the BootRom Menu until the issue is resolved, and restrict access to the upgrade functionality for the small BootRom/main BootRom or FPGA/CPLD software.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Campus S7700
Huawei Campus S9300
Huawei Campus S9700
Huawei Vrp