This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
User permissions are not properly set on Huawei eSpace Meeting. Attackers that obtain the permissions assigned to common users can elevate privileges to access and set specific key resources. (HWPSIRT-2014-0241).
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-3222.
eSpace Meeting series products |
|
eSpace Meeting |
V100R001C03SPC201 and the earlier versions |
Attackers elevate privileges to access and set specific key resources.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 6.2 (AV:L/AC:M/Au:S/C:C/I:C/A:P)
Temporal Score: 4.9 (E:P/RL:O/RC:C)
1. Prerequisite:
Attackers obtain the permissions of common users and can access the installation directory of eSpace Meeting.
2. Attacking procedure:
With the permissions of common users, attackers use specific attack means to change the system status to make a privilege elevation.
Null
Upgrading version and upgrading date:
Product name |
Solved version |
Solved time |
eSpace Meeting |
V100R001C03SPC202 |
Released |
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades, or obtain them through Huawei worldwide website at http://support.huawei.com/enterprise/. For TAC contact information, please refer to Huawei worldwide website at http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htm.
This vulnerability is found by Gjoko Krstic (gjoko@zeroscience.mk). The Huawei PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Huawei express our appreciation for Gjoko Krstic’s concerns on Huawei products.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2014-10-08 V1.2 UPDATED correct the data information error
2014-05-12 V1.1 UPDATED add the CVE ID
2014-03-10 V1.0 INITIAL