SB2016100413 - Password leak in Huawei S5300
Published: October 4, 2016 Updated: January 17, 2020
Security Bulletin ID
SB2016100413
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Password leak (CVE-ID: CVE-2015-8086)
The vulnerability allows a remote authenticated administrators to obtain confidential information on the target system.The weakness is caused by insufficient access control. By using vectors related to key storage attackers can access encryption keys and ciphertext passwords.
Successful exploitation of the vulnerability leads to passwords leak on the vulnerable system.
Remediation
Install update from vendor's website.