PT-2015-7724 · Huawei · Quidway S9300+7
Aristide Fattori
+1
·
Publicado
2015-09-30
·
Atualizado
2016-11-28
·
CVE-2015-8086
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei AR routers versions prior to V200R007C00SPC100
Quidway S9300 routers versions prior to V200R009C00
S12700 routers versions prior to V200R008C00SPC500
S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00
S5700 routers versions prior to V200R007C00SPC500
Description
The issue makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage. Encryption keys are stored in the system, allowing an attacker to implement reverse engineering to obtain the encryption keys.
Recommendations
For Huawei AR routers versions prior to V200R007C00SPC100, update to V200R007C00SPC100 or later.
For Quidway S9300 routers versions prior to V200R009C00, update to V200R009C00 or later.
For S12700 routers versions prior to V200R008C00SPC500, update to V200R008C00SPC500 or later.
For S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00, update to V200R007C00 or later.
For S5700 routers versions prior to V200R007C00SPC500, update to V200R007C00SPC500 or later.
Correção
Inadequate Encryption Strength
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Ar
Huawei Vrp
Quidway S5300
Quidway S9300
S12700
S5300
S5700
S9300