PT-2017-6384 · Huawei · Huawei Tecal Rh2288H V2+23
Published
2017-04-02
·
Updated
2017-04-05
·
CVE-2014-9691
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei Tecal RH1288 V2 versions V100R002C00SPC107 and earlier
Huawei Tecal RH2265 V2 version V100R002C00
Huawei Tecal RH2285 V2 versions V100R002C00SPC115 and earlier
Huawei Tecal RH2268 V2 version V100R002C00
Huawei Tecal RH2288 V2 versions V100R002C00SPC117 and earlier
Huawei Tecal RH2288H V2 versions V100R002C00SPC115 and earlier
Huawei Tecal RH2485 V2 versions V100R002C00SPC502 and earlier
Huawei Tecal RH5885 V2 versions V100R001C02SPC109 and earlier
Huawei Tecal RH5885 V3 versions V100R003C01SPC102 and earlier
Huawei Tecal RH5885H V3 versions V100R003C00SPC102 and earlier
Huawei Tecal XH310 V2 versions V100R001C00SPC110 and earlier
Huawei Tecal XH311 V2 versions V100R001C00SPC110 and earlier
Huawei Tecal XH320 V2 versions V100R001C00SPC110 and earlier
Huawei Tecal XH621 V2 versions V100R001C00SPC106 and earlier
Huawei Tecal DH310 V2 versions V100R001C00SPC110 and earlier
Huawei Tecal DH320 V2 versions V100R001C00SPC106 and earlier
Huawei Tecal DH620 V2 versions V100R001C00SPC106 and earlier
Huawei Tecal DH621 V2 versions V100R001C00SPC107 and earlier
Huawei Tecal DH628 V2 versions V100R001C00SPC107 and earlier
Huawei Tecal BH620 V2 versions V100R002C00SPC107 and earlier
Huawei Tecal BH621 V2 versions V100R002C00SPC106 and earlier
Huawei Tecal BH622 V2 versions V100R002C00SPC110 and earlier
Huawei Tecal BH640 V2 versions V100R002C00SPC108 and earlier
Huawei Tecal CH121 version V100R001C00SPC180 and earlier
Huawei Tecal CH140 version V100R001C00SPC110 and earlier
Huawei Tecal CH220 version V100R001C00SPC180 and earlier
Huawei Tecal CH221 version V100R001C00SPC180 and earlier
Huawei Tecal CH222 versions V100R002C00SPC180 and earlier
Huawei Tecal CH240 version V100R001C00SPC180 and earlier
Huawei Tecal CH242 version V100R001C00SPC180 and earlier
Huawei Tecal CH242 V3 versions V100R001C00SPC110 and earlier
Description
The issue allows users who log in to the products to view the session IDs of all online users on the Online Users page of the web UI.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Tecal Bh620 V2
Huawei Tecal Bh621 V2
Huawei Tecal Bh622 V2
Huawei Tecal Bh640 V2
Huawei Tecal Ch121
Huawei Tecal Ch140
Huawei Tecal Ch220
Huawei Tecal Ch221
Huawei Tecal Ch222
Huawei Tecal Ch240
Huawei Tecal Ch242
Huawei Tecal Ch242 V3
Huawei Tecal Dh310 V2
Huawei Tecal Dh320 V2
Huawei Tecal Dh628 V2
Huawei Tecal Rh1288 V2
Huawei Tecal Rh2265 V2
Huawei Tecal Rh2268 V2
Huawei Tecal Rh2285 V2
Huawei Tecal Rh2288H V2
Huawei Tecal Rh2485 V2
Huawei Tecal Rh5885 V2
Huawei Tecal Rh5885H V3
Huawei Tecal Xh311 V2