First published: Mon Jan 11 2016(Updated: )
Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei VCN500 | =v100r002c00spc200 | |
Huawei VCN500 | =v100r002c00spc200b010 | |
Huawei VCN500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8335 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2015-8335, upgrade the Huawei VCN500 to software version V100R002C00SPC201 or later.
Users of the Huawei VCN500 running versions before V100R002C00SPC201 are affected by CVE-2015-8335.
CVE-2015-8335 exposes passwords logged in cleartext to remote authenticated users.
CVE-2015-8335 is still exploitable if devices are running affected versions of the Huawei VCN500 software.