PT-2015-7750 · Huawei · Huawei Ar Routers+1

Publicado

2015-11-11

·

Atualizado

2015-11-25

·

CVE-2015-8228

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei AR routers versions before V200R006SPH003
Description The issue allows remote authenticated users to access arbitrary directories via unspecified vectors, potentially leading to information leaks. An attacker can log in to the router and traverse FTP server directories to access unauthorized directories.
Recommendations For versions before V200R006SPH003, update to V200R006SPH003 or later to resolve the issue. As a temporary workaround, consider restricting access to the SFTP server to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8228

Produtos afetados

Huawei Ar Routers
Huawei Vrp