Vulnerability Description
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Hedex Lite | < v200r006c00 |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20170531-01-heIssue TrackingVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20170531-01-heIssue TrackingVendor Advisory
FAQ
What is CVE-2017-8139?
CVE-2017-8139 is a vulnerability with a CVSS score of 6.1 (MEDIUM). HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to inte...
How severe is CVE-2017-8139?
CVE-2017-8139 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8139?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Hedex Lite.