First published: Mon Oct 03 2016(Updated: )
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Campus S9300 Firmware | =v200r005c00spc300 | |
Huawei Campus S9300 Firmware | =v200r006c00spc500 | |
Huawei Campus S9300 | ||
Huawei S12700 Firmware | =v200r005c00 | |
Huawei S12700 Firmware | =v200r006c00 | |
Huawei S12700 Firmware | ||
Huawei Quidway S9300 Firmware | =v200r001c00spc300 | |
Huawei Quidway S9300 Firmware | =v200r002c00spc100 | |
Huawei Quidway S9300 Firmware | =v200r003c00spc500 | |
Huawei Quidway Service Process Unit Board S9300 | ||
Huawei AR firmware | =v200r001 | |
Huawei AR firmware | =v200r002 | |
Huawei AR firmware | =v200r003 | |
Huawei AR firmware | =v200r005c10 | |
Huawei AR firmware | =v200r005c20 | |
Huawei AR firmware | =v200r005c30 | |
Huawei AR | ||
Huawei Quidway S5300 firmware | =v200r001c00spc300 | |
Huawei Quidway S5300 firmware | ||
Huawei S5700HI Firmware | =v200r001c00 | |
Huawei S5700HI Firmware | =v200r002c00 | |
Huawei S5700HI Firmware | =v200r003c00 | |
Huawei S5700HI Firmware | =v200r005c00 | |
Huawei S5700HI Firmware | =v200r006c00 | |
Huawei S5700 Firmware | ||
Huawei S5300HI Firmware | =v200r002c00 | |
Huawei S5300HI Firmware | =v200r005c00spc500 | |
Huawei S5300HI Firmware | =v200r006c00spc500 | |
Huawei S5306 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8085 has a critical severity rating due to potential remote execution of arbitrary commands.
To fix CVE-2015-8085, update the affected Huawei AR and Quidway router firmware to the latest versions specified in the advisory.
CVE-2015-8085 affects several Huawei AR routers and Quidway series routers with specific firmware versions prior to the updates.
Yes, CVE-2015-8085 can be exploited remotely, potentially allowing unauthorized access to affected devices.
CVE-2015-8085 represents vulnerabilities related to improper input validation and excessive privileges on impacted Huawei routers.