PT-2017-9798 · Huawei · Utps
Dhruv Shah
+1
·
Publicado
2017-04-02
·
Atualizado
2024-02-14
·
CVE-2016-8769
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei UTPS versions earlier than UTPS-V200R003B015D16SPC00C983
Description
The issue is related to an unquoted service path, which can lead to the truncation of service query paths. An attacker may exploit this by placing an executable file in the search path of the affected service, potentially obtaining elevated privileges after the executable file is executed.
Recommendations
For versions earlier than UTPS-V200R003B015D16SPC00C983, update to UTPS-V200R003B015D16SPC00C983 or later to resolve the issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Utps