MEDIUM · 4.8

CVE-2012-5968

The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to t...

Vulnerability Description

The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.

CVSS Score

4.8

MEDIUM

AV:A/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HuaweiE585-
HuaweiE585U-82-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5968?

CVE-2012-5968 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to t...

How severe is CVE-2012-5968?

CVE-2012-5968 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5968?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei E585, Huawei E585U-82.