PT-2016-3945 · Huawei · Huawei S5300 Campus Series+1

Publicado

2016-01-12

·

Atualizado

2016-01-21

·

CVE-2015-8675

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei S5300 Campus Series switches versions prior to V200R005SPH008
Description The issue concerns an information exposure problem where passwords are not masked when uploading files to certain directories, allowing physically proximate attackers to obtain sensitive password information by reading the display. This occurs because the system does not hide passwords entered by the user, leading to potential password leaks.
Recommendations For versions prior to V200R005SPH008, consider disabling the file upload feature to the affected directories until a patch is available. Restrict physical access to the switches to minimize the risk of exploitation. Update to a version V200R005SPH008 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8675

Produtos afetados

Huawei S5300 Campus Series
Huawei Vrp