This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
When a Huawei UDS product is loading a patch, an attacker can intercept and change the patch loading information and compromise certain directory files of the device (Vulnerability ID: HWPSIRT-2014-1238).
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-2254.
Product Name |
Affected Version |
Resolved Product and Version |
OceanStor UDS |
V100R002C01SPC101 and earlier versions |
V100R002C01SPC102 |
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 5.8 (AV:N/AC:M/Au:N/C:N/I:P/A:P)
Temporal Score: 4.8 (E:F/RL:O/RC:C)1. Prerequisite:
The attacker gains access to the OceanStor UDS network.
The UDS is loading a patch.
2. Attacking procedure:
The attacker captures and changes the patch loading information to delete certain directory files and compromise some system functions.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
None