This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Huawei LogCenter has a privilege escalation vulnerability. After login to the LogCenter, a low privileged attacker can tamper with requests using a tool and submit the request to the server for privilege escalation, affecting some system functions. (Vulnerability ID: HWPSIRT-2015-09020)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8671.
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link: http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-464243.htm
Product Name |
Affected Version |
Resolved Product and Version |
LogCenter |
V100R001C10 |
V100R001C10SPC300B018 |
The attacker can exploit this vulnerability to escalate privileges and affect some system functions.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 6.5 (AV:N/AC:L/Au:S/C:P/I:P/A:P)
Temporal Score: 5.4 (E:F/RL:O/RC:C)
1. Prerequisite:
The attacker has logged in to the device.
2. Attacking procedure:
Huawei LogCenter has a vulnerability in the user authentication function. An attacker can tamper with requests and submit the requests to a server for privilege escalation, affecting some system functions.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
None