PT-2015-7750 · Huawei · Huawei Ar Routers+1
Publicado
2015-11-11
·
Atualizado
2015-11-25
·
CVE-2015-8228
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei AR routers versions before V200R006SPH003
Description
The issue allows remote authenticated users to access arbitrary directories via unspecified vectors, potentially leading to information leaks. An attacker can log in to the router and traverse FTP server directories to access unauthorized directories.
Recommendations
For versions before V200R006SPH003, update to V200R006SPH003 or later to resolve the issue. As a temporary workaround, consider restricting access to the SFTP server to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Ar Routers
Huawei Vrp