PT-2017-18147 · Huawei · Hedex
-Rwx------
·
Published
2017-11-22
·
Updated
2017-12-08
·
CVE-2017-8138
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HedEx versions earlier than V200R006C00
Description
The issue allows an attacker to trick a user into accessing a website containing malicious scripts, potentially tampering with configurations and interrupting normal services due to a cross-site request forgery (CSRF) issue.
Recommendations
For versions earlier than V200R006C00, update to V200R006C00 or later to resolve the issue.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hedex