Vulnerability Description
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Oceanstor Uds Firmware | <= v100r002c01spc101 |
| Huawei | Oceanstor Uds | - |
Related Weaknesses (CWE)
References
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/Vendor Advisory
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/Vendor Advisory
FAQ
What is CVE-2015-2253?
CVE-2015-2253 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
How severe is CVE-2015-2253?
CVE-2015-2253 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2253?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Oceanstor Uds Firmware, Huawei Oceanstor Uds.