Vulnerability Description
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | S9300 Firmware | v200r001c00spc300 |
| Huawei | S9300 | - |
| Huawei | S9300E Firmware | v200r001c00spc300 |
| Huawei | S9300E | - |
| Huawei | S7700 Firmware | v200r001c00spc300 |
| Huawei | S7700 | - |
| Huawei | S9700 Firmware | v200r001c00spc300 |
| Huawei | S9700 | - |
| Huawei | S5700 Firmware | v200r001c00spc300 |
| Huawei | S5700 | - |
| Huawei | S6700 Firmware | v200r001c00spc300 |
| Huawei | S6700 | - |
| Huawei | S5300 Firmware | v200r001c00spc300 |
| Huawei | S5300 | - |
| Huawei | S6300 Firmware | v200r001c00spc300 |
| Huawei | S6300 | - |
| Huawei | S2300 Firmware | v100r006c05 |
| Huawei | S2300 | - |
| Huawei | S2700 Firmware | v100r006c05 |
| Huawei | S2700 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/us/psirt/security-advisories/2014/hw-362701Vendor Advisory
- http://www.securityfocus.com/bid/69302Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97763Third Party AdvisoryVDB Entry
- http://www.huawei.com/us/psirt/security-advisories/2014/hw-362701Vendor Advisory
- http://www.securityfocus.com/bid/69302Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/97763Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-5394?
CVE-2014-5394 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
How severe is CVE-2014-5394?
CVE-2014-5394 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-5394?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei S9300 Firmware, Huawei S9300, Huawei S9300E Firmware, Huawei S9300E, Huawei S7700 Firmware.