This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
This security advisory (SA) describes the impact of DLL-Hijacking vulnerability discovered in website. (Vulnerability ID: HWPSIRT-2014-1046)
This vulnerability is referenced in this document as follows:
Any user in the system can modify the legitimate binary to any kind of malicious executable. If an attacker breakinto a low privilege account he could use this application to escalate his privileges.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8358.
The user could also place a malicious wintab32.dll file inside the "Mobile Partner" folder and perform DLL hijacking.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8359.
Product Name |
Affected Version |
Solved version |
EC177 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
EC176 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
EC156 |
UTPS-V200R003B009D05SP03C1014 (23.009.05.03.1014) |
UTPS-V200R003B015D02SP08C1014(23.015.02.08.1014) UTPS-V200R003B015D02SP07C1014( 23.015.02.07.1014) |
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
CVE-2014-8358:
Base Score: 6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Temporal Score: 5.0 (E:F/RL:O/RC:C)
Overall Score: 5.0
CVE-2014-8359:
Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Temporal Score: 5.0 (E:F/RL:O/RC:C)
Overall Score: 5.0For additional details, customers are advised to reference the website link:
http://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades, or obtain them through Huawei worldwide website at http://support.huawei.com/support/.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
None