PT-2017-9798 · Huawei · Utps

Dhruv Shah

+1

·

Published

2017-04-02

·

Updated

2024-02-14

·

CVE-2016-8769

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei UTPS versions earlier than UTPS-V200R003B015D16SPC00C983
Description The issue is related to an unquoted service path, which can lead to the truncation of service query paths. An attacker may exploit this by placing an executable file in the search path of the affected service, potentially obtaining elevated privileges after the executable file is executed.
Recommendations For versions earlier than UTPS-V200R003B015D16SPC00C983, update to UTPS-V200R003B015D16SPC00C983 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8769

Affected Products

Utps