PT-2014-6067 · Huawei · Huawei Campus S7700+3

Published

2014-05-07

·

Updated

2017-04-06

·

CVE-2014-4707

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300 Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300 Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300
Description The issue allows unauthorized users to upgrade the bootrom or bootload software, bypass a Menu protection mechanism, conduct a Menu compromise attack, or bypass a Menu/upgrade protection mechanism. This can be achieved through the BootRom and Boot Menu vulnerability, which enables unauthorized users to bypass the system security check mechanism and compromise the switch.
Recommendations For Huawei Campus S7700 versions V200R001C00SPC300 through V200R003C00SPC300, restrict access to the bootrom and bootload software upgrade functionality until a patch is available. For Huawei Campus S9300 versions V200R001C00SPC300 through V200R003C00SPC300, consider disabling the Boot Menu to prevent unauthorized upgrades and bypassing of the system security check mechanism. For Huawei Campus S9700 versions V200R001C00SPC300 through V200R003C00SPC300, avoid using the BootRom Menu until the issue is resolved, and restrict access to the upgrade functionality for the small BootRom/main BootRom or FPGA/CPLD software.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4707

Affected Products

Huawei Campus S7700
Huawei Campus S9300
Huawei Campus S9700
Huawei Vrp