PT-2014-6067 · Huawei · Huawei Campus S7700+3
Published
2014-05-07
·
Updated
2017-04-06
·
CVE-2014-4707
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300
Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300
Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300
Description
The issue allows unauthorized users to upgrade the bootrom or bootload software, bypass a Menu protection mechanism, conduct a Menu compromise attack, or bypass a Menu/upgrade protection mechanism. This can be achieved through the BootRom and Boot Menu vulnerability, which enables unauthorized users to bypass the system security check mechanism and compromise the switch.
Recommendations
For Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300, restrict access to the bootrom and bootload software upgrade functionality until a patch is available.
For Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300, consider disabling the Boot Menu to prevent unauthorized upgrades and bypassing of the system security check mechanism.
For Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300, avoid using the BootRom Menu until the issue is resolved, and restrict access to the upgrade functionality for the small BootRom/main BootRom or FPGA/CPLD software.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Campus S7700
Huawei Campus S9300
Huawei Campus S9700
Huawei Vrp