PT-2017-9588 · Huawei · Huawei Hisuite

Florian Bogner

·

Published

2017-04-02

·

Updated

2017-04-05

·

CVE-2016-8273

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei HiSuite version 4.0.5.300 OVE
Description The issue concerns the use of insecure HTTP for software package downloads and the lack of integrity checks on the downloaded packages. This allows an attacker to potentially launch a Man-In-The-Middle (MITM) attack, interrupting or replacing the software package, which could further compromise the PC.
Recommendations For Huawei HiSuite version 4.0.5.300 OVE, consider disabling the automatic software update feature until a secure update mechanism is implemented. Restrict access to the upgrade software package download feature to minimize the risk of exploitation. Avoid using insecure HTTP connections for software package downloads; instead, use a secure connection such as HTTPS. As a temporary workaround, manually verify the integrity of the software package before installing it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8273

Affected Products

Huawei Hisuite