MEDIUM · 6.1

CVE-2016-8789

Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicio...

Vulnerability Description

Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
HuaweiEspace Integrated Access Device Firmwarev300r001c03
HuaweiEspace Integrated Access Device-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-8789?

CVE-2016-8789 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicio...

How severe is CVE-2016-8789?

CVE-2016-8789 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-8789?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Espace Integrated Access Device Firmware, Huawei Espace Integrated Access Device.