PT-2015-7724 · Huawei · Quidway S9300+7

Aristide Fattori

+1

·

Publicado

2015-09-30

·

Atualizado

2016-11-28

·

CVE-2015-8086

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei AR routers versions prior to V200R007C00SPC100 Quidway S9300 routers versions prior to V200R009C00 S12700 routers versions prior to V200R008C00SPC500 S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00 S5700 routers versions prior to V200R007C00SPC500
Description The issue makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage. Encryption keys are stored in the system, allowing an attacker to implement reverse engineering to obtain the encryption keys.
Recommendations For Huawei AR routers versions prior to V200R007C00SPC100, update to V200R007C00SPC100 or later. For Quidway S9300 routers versions prior to V200R009C00, update to V200R009C00 or later. For S12700 routers versions prior to V200R008C00SPC500, update to V200R008C00SPC500 or later. For S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00, update to V200R007C00 or later. For S5700 routers versions prior to V200R007C00SPC500, update to V200R007C00SPC500 or later.

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8086

Produtos afetados

Huawei Ar
Huawei Vrp
Quidway S5300
Quidway S9300
S12700
S5300
S5700
S9300