CVE-2015-2252: Code Injection
Published Jun 8, 2017
·Updated
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.
Affected Software
2 affected components
Huawei Oceanstor Uds Firmware<=v100r002c01spc101
Huawei OceanStor UDS
Event History
Jun 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2252?
CVE-2015-2252 is considered critical as it allows remote attackers to execute arbitrary code with root privileges.
2
How do I fix CVE-2015-2252?
To fix CVE-2015-2252, update the Huawei OceanStor UDS firmware to version V100R002C01SPC102 or later.
3
Which versions are affected by CVE-2015-2252?
CVE-2015-2252 affects Huawei OceanStor UDS devices with software versions prior to V100R002C01SPC102.
4
What are the potential impacts of CVE-2015-2252?
The potential impacts of CVE-2015-2252 include unauthorized access and control over the affected devices.
5
Is CVE-2015-2252 a local or remote vulnerability?
CVE-2015-2252 is a remote vulnerability that can be exploited by attackers without physical access to the device.