PT-2017-9588 · Huawei · Huawei Hisuite
Florian Bogner
·
Published
2017-04-02
·
Updated
2017-04-05
·
CVE-2016-8273
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei HiSuite version 4.0.5.300 OVE
Description
The issue concerns the use of insecure HTTP for software package downloads and the lack of integrity checks on the downloaded packages. This allows an attacker to potentially launch a Man-In-The-Middle (MITM) attack, interrupting or replacing the software package, which could further compromise the PC.
Recommendations
For Huawei HiSuite version 4.0.5.300 OVE, consider disabling the automatic software update feature until a secure update mechanism is implemented. Restrict access to the upgrade software package download feature to minimize the risk of exploitation. Avoid using insecure HTTP connections for software package downloads; instead, use a secure connection such as HTTPS. As a temporary workaround, manually verify the integrity of the software package before installing it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei Hisuite