Vulnerability Description
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Oceanstor Uds Firmware | <= v100r002c01spc101 |
| Huawei | Oceanstor Uds | - |
Related Weaknesses (CWE)
References
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/Vendor Advisory
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/Vendor Advisory
FAQ
What is CVE-2015-2251?
CVE-2015-2251 is a vulnerability with a CVSS score of 7.5 (HIGH). The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
How severe is CVE-2015-2251?
CVE-2015-2251 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2251?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Oceanstor Uds Firmware, Huawei Oceanstor Uds.