CVE-2014-9137: CSRF
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9137?
CVE-2014-9137 is classified as a critical vulnerability that allows unauthenticated remote attackers to execute Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2014-9137?
To mitigate CVE-2014-9137, users should upgrade to the latest firmware versions provided by Huawei for the affected USG series devices.
Which Huawei devices are affected by CVE-2014-9137?
CVE-2014-9137 affects Huawei USG9500, USG2100, USG2200, and USG5100 series devices running specified versions of their firmware.
Can CVE-2014-9137 be exploited remotely?
Yes, CVE-2014-9137 can be exploited by an unauthenticated remote attacker without the need for user interaction.
What types of attacks can result from CVE-2014-9137?
CVE-2014-9137 can lead to CSRF attacks, potentially allowing attackers to perform unauthorized actions on behalf of the user.