First published: Mon Aug 28 2017(Updated: )
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal Privilege Escalation Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Vcm5010 Firmware | <=v100r001c10b010 | |
Huawei Vcm5010 | ||
Huawei Vcm5020 Firmware | <=v100r001c10b010 | |
Huawei Vcm5020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8332 is classified as a medium severity vulnerability due to its potential for horizontal privilege escalation.
To fix CVE-2015-8332, upgrade to Huawei VCM firmware version V100R001C10SPC001 or later.
CVE-2015-8332 allows remote authenticated users to escalate privileges and perform operations as other users without proper authentication.
CVE-2015-8332 affects Huawei VCM5010 and VCM5020 firmware versions up to V100R001C10B010.
The responsibility for addressing CVE-2015-8332 falls on users of the affected Huawei VCM systems, who should apply the necessary firmware updates.