MEDIUM · 4.6

CVE-2015-7846

Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

Vulnerability Description

Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

CVSS Score

4.6

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HuaweiS9300 Firmwarev200r001c00spc300
HuaweiS9300-
HuaweiS9700 Firmwarev200r001c00spc300
HuaweiS9700-
HuaweiS7700 Firmwarev200r001c00spc300
HuaweiS7700-
HuaweiAr200 Firmwarev200r003c00spc100
HuaweiAr200-
HuaweiAr1200 Firmwarev200r003c00spc100
HuaweiAr1200-
HuaweiAr2200 Firmwarev200r003c00spc100
HuaweiAr2200-
HuaweiAr3200 Firmwarev200r003c00spc100
HuaweiAr3200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7846?

CVE-2015-7846 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

How severe is CVE-2015-7846?

CVE-2015-7846 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7846?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei S9300 Firmware, Huawei S9300, Huawei S9700 Firmware, Huawei S9700, Huawei S7700 Firmware.