PT-2018-5800 · Huawei · Huawei Oceanstor 5300 V3+4
Published
2018-02-15
·
Updated
2019-10-03
·
CVE-2017-15352
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Huawei OceanStor 2800 V3 versions V300R003C00 through V300R003C20
Huawei OceanStor 5300 V3 versions V300R003C00 through V300R003C20
Huawei OceanStor 5500 V3 versions V300R003C00 through V300R003C20
Huawei OceanStor 5600 V3 versions V300R003C00 through V300R003C20
Huawei OceanStor 5800 V3 versions V300R003C00 through V300R003C20
Description:
The issue is related to improper access control, where access to a resource is not correctly restricted. This could allow an attacker with high privilege to exploit the vulnerability, potentially querying some information or sending specific messages that could cause service abnormalities.
Recommendations:
For Huawei OceanStor 2800 V3 versions V300R003C00 through V300R003C20, update to a version that properly restricts access to the vulnerable resource.
For Huawei OceanStor 5300 V3 versions V300R003C00 through V300R003C20, update to a version that properly restricts access to the vulnerable resource.
For Huawei OceanStor 5500 V3 versions V300R003C00 through V300R003C20, update to a version that properly restricts access to the vulnerable resource.
For Huawei OceanStor 5600 V3 versions V300R003C00 through V300R003C20, update to a version that properly restricts access to the vulnerable resource.
For Huawei OceanStor 5800 V3 versions V300R003C00 through V300R003C20, update to a version that properly restricts access to the vulnerable resource.
As a temporary workaround, consider restricting access to the vulnerable resource until a patch is available.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Oceanstor 2800 V3
Huawei Oceanstor 5300 V3
Huawei Oceanstor 5500 V3
Huawei Oceanstor 5600 V3
Huawei Oceanstor 5800 V3