First published: Wed Dec 19 2012(Updated: )
The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei E585 | ||
Huawei E585u-82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5968 has a medium severity rating due to the potential for sensitive user information exposure.
To fix CVE-2012-5968, you should update the firmware of the Huawei E585 device to the latest version provided by the manufacturer.
CVE-2012-5968 affects the Huawei E585 and Huawei E585u-82 devices.
Attackers exploiting CVE-2012-5968 can obtain sensitive user information, including session IDs, and potentially modify data.
No, CVE-2012-5968 is not a remote code execution vulnerability but rather a session management issue that allows information leakage.