PT-2015-7723 · Huawei · S5700 Routers+7

Aristide Fattori

+1

·

Published

2015-09-30

·

Updated

2016-11-28

·

CVE-2015-8085

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei AR routers versions prior to V200R007C00SPC100 Quidway S9300 routers versions prior to V200R009C00 S12700 routers versions prior to V200R008C00SPC500 S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00 S5700 routers versions prior to V200R007C00SPC500
Description The issue allows remote authenticated administrators to obtain and decrypt passwords by leveraging the selection of a reversible encryption algorithm. This is caused by improper encryption mechanisms in some Huawei products, where users can choose between reversible or irreversible encryption algorithms to encrypt passwords. If a reversible encryption algorithm is used, an attacker with high administrative privileges can log in to the device, obtain the ciphertext password of a higher-level administrator, and potentially crack it to gain elevated privileges.
Recommendations For Huawei AR routers versions prior to V200R007C00SPC100, update to V200R007C00SPC100 or later. For Quidway S9300 routers versions prior to V200R009C00, update to V200R009C00 or later. For S12700 routers versions prior to V200R008C00SPC500, update to V200R008C00SPC500 or later. For S9300, Quidway S5300, and S5300 routers versions prior to V200R007C00, update to V200R007C00 or later. For S5700 routers versions prior to V200R007C00SPC500, update to V200R007C00SPC500 or later.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8085

Affected Products

Huawei Ar Routers
Huawei Vrp
Quidway S5300 Routers
Quidway S9300 Routers
S12700 Routers
S5300 Routers
S5700 Routers
S9300 Routers