Vulnerability Description
The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissions on the PrintScreen button.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Document Security Management | <= v100r002c05spc661 |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160218-01-dsm-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160218-01-dsm-enVendor Advisory
FAQ
What is CVE-2016-2406?
CVE-2016-2406 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by le...
How severe is CVE-2016-2406?
CVE-2016-2406 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2406?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Document Security Management.