Vulnerability Description
Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exploitation may cause information leak.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Hg8245H Firmware | < v300r018c00spc110 |
| Huawei | Hg8245H | - |
Related Weaknesses (CWE)
References
- http://support.huawei.com/carrier/docview%21docview?nid=DOC1000441394&path=PBI1-
- https://hacked0x90.wordpress.com/2017/11/30/hg8245h-authentication-bypass/Third Party Advisory
- http://support.huawei.com/carrier/docview%21docview?nid=DOC1000441394&path=PBI1-
- https://hacked0x90.wordpress.com/2017/11/30/hg8245h-authentication-bypass/Third Party Advisory
FAQ
What is CVE-2017-15328?
CVE-2017-15328 is a vulnerability with a CVSS score of 7.5 (HIGH). Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privi...
How severe is CVE-2017-15328?
CVE-2017-15328 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15328?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Hg8245H Firmware, Huawei Hg8245H.