PT-2017-9798 · Huawei · Utps
Dhruv Shah
+1
·
Published
2017-04-02
·
Updated
2024-02-14
·
CVE-2016-8769
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei UTPS versions earlier than UTPS-V200R003B015D16SPC00C983
Description
The issue is related to an unquoted service path, which can lead to the truncation of service query paths. An attacker may exploit this by placing an executable file in the search path of the affected service, potentially obtaining elevated privileges after the executable file is executed.
Recommendations
For versions earlier than UTPS-V200R003B015D16SPC00C983, update to UTPS-V200R003B015D16SPC00C983 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Utps