MEDIUM · 4.8

CVE-2012-5969

Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitr...

Vulnerability Description

Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (dot dot) in the req_page parameter to en/sms.cgi.

CVSS Score

4.8

MEDIUM

AV:A/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HuaweiE585-
HuaweiE585U-82-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5969?

CVE-2012-5969 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitr...

How severe is CVE-2012-5969?

CVE-2012-5969 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5969?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei E585, Huawei E585U-82.