VulnerabilityModified
CVE-2016-8769
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths.
MEDIUM 6.7EPSS 1.58%
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- huawei/utps firmware
- Source
- psirt@huawei.com
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-enVendor Advisory
- http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/Third Party Advisory, URL Repurposed
- http://www.securityfocus.com/bid/94403Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40807/Third Party Advisory, VDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-enVendor Advisory
- http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/Third Party Advisory, URL Repurposed
- http://www.securityfocus.com/bid/94403Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/40807/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.