CVE-2012-6571: High severity Huawei Ar 18-1x vulnerability
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6571?
CVE-2012-6571 is classified as a high severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2012-6571?
To fix CVE-2012-6571, update your Huawei devices to the latest firmware versions that address this vulnerability.
What products are affected by CVE-2012-6571?
CVE-2012-6571 affects multiple Huawei products, including certain models of AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches.
How does CVE-2012-6571 allow attackers to exploit systems?
CVE-2012-6571 allows attackers to exploit systems by leveraging predictable Session ID values to hijack active sessions.
What should I do if I cannot update my devices to mitigate CVE-2012-6571?
If you cannot update your devices to mitigate CVE-2012-6571, consider implementing additional security measures, such as network segmentation and enhanced monitoring.