This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
VSM (Versatile Security Manager) is a unified security service management system launched by Huawei for carrier and enterprise customers.
VSM contains a vulnerability that default user groups’ privilege could be escalated when one user logs in to the system to modify default user groups’ permission configurations. The vulnerability is due to improper validation of authentication to the accessed user account (Vulnerability ID: HWNSIRT-2013-0302).
Currently, the official version VSM V200R002C00SPC300 has been released to fix this vulnerability.
Product Name |
Affected Version |
Resolved Product and Version |
Seco VSM |
V200R002C00 |
V200R002C00SPC300 |
V200R002C00SPC100 |
||
V200R002C00SPC200 |
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
The score of the vulnerability is following:
Base Score: 9.0(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Temporal Score: 7.5 (E:F/RL:O/RC:C)
Overall Score: 7.5
Vulnerability exploitation prerequisites:
The attacker can access VSM system,
The attacker has VSM user account and password.
Vulnerability details:
Any user in the VSM default user groups can change default groups’ privilege configuration without specific authentication after it logs in to the VSM system, and then it may cause the privilege escalation of the default user group in VSM.
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades, or obtain them through Huawei Enterprise worldwide website at http://support.huawei.com/enterprise/. For TAC contact information, please refer to Huawei worldwide website at http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htm.
The link for VSM V200R002C00SPC300:
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2013-04-03 V1.0 INITIAL
2013-04-20 V1.1 UPDATED update CVSS score
None