PT-2017-9588 · Huawei · Huawei Hisuite

Florian Bogner

·

Publicado

2017-04-02

·

Atualizado

2017-04-05

·

CVE-2016-8273

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei HiSuite version 4.0.5.300 OVE
Description The issue concerns the use of insecure HTTP for software package downloads and the lack of integrity checks on the downloaded packages. This allows an attacker to potentially launch a Man-In-The-Middle (MITM) attack, interrupting or replacing the software package, which could further compromise the PC.
Recommendations For Huawei HiSuite version 4.0.5.300 OVE, consider disabling the automatic software update feature until a secure update mechanism is implemented. Restrict access to the upgrade software package download feature to minimize the risk of exploitation. Avoid using insecure HTTP connections for software package downloads; instead, use a secure connection such as HTTPS. As a temporary workaround, manually verify the integrity of the software package before installing it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8273

Produtos afetados

Huawei Hisuite