PT-2017-6234 · Huawei · Huawei Ec176+3
Published
2017-12-11
·
Updated
2017-12-29
·
CVE-2014-8358
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014)
Description
The issue allows remote attackers to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe, due to a weak ACL for the "Mobile Partner" directory.
Recommendations
For Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014), update to a version that includes the necessary security patches to strengthen the ACL for the "Mobile Partner" directory.
As a temporary workaround, consider restricting access to the "Mobile Partner" directory to minimize the risk of exploitation.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ec156
Huawei Ec176
Huawei Ec177
Mobile Partner