PT-2017-6234 · Huawei · Huawei Ec176+3

Published

2017-12-11

·

Updated

2017-12-29

·

CVE-2014-8358

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014)
Description The issue allows remote attackers to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe, due to a weak ACL for the "Mobile Partner" directory.
Recommendations For Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014), update to a version that includes the necessary security patches to strengthen the ACL for the "Mobile Partner" directory. As a temporary workaround, consider restricting access to the "Mobile Partner" directory to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8358

Affected Products

Huawei Ec156
Huawei Ec176
Huawei Ec177
Mobile Partner