CVE-2016-2404: High severity huawei s5700hi firmware vulnerability
Huawei switches S5700, S6700, S7700, S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300, V200R005C00SPC500, V200R006C00; S12700 with software V200R005C00SPC500, V200R006C00; ACU2 with software V200R005C00SPC500, V200R006C00 have a permission control vulnerability. If a switch enables Authentication, Authorization, and Accounting (AAA) for permission control and user permissions are not appropriate, AAA users may obtain the virtual type terminal (VTY) access permission, resulting in privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2404?
The severity of CVE-2016-2404 is rated as high due to the permission control vulnerability that can lead to unauthorized access.
How do I fix CVE-2016-2404?
To fix CVE-2016-2404, upgrade the affected Huawei switch firmware to a version that is not vulnerable, specifically V200R001C00SPC500 or newer.
What devices are affected by CVE-2016-2404?
Devices affected by CVE-2016-2404 include Huawei S5700, S6700, S7700, S9700, S12700, and ACU2 models running specific older firmware versions.
Is there a workaround for CVE-2016-2404?
There are no known workarounds for CVE-2016-2404, and updating the firmware is the recommended action.
What impact does CVE-2016-2404 have on network security?
CVE-2016-2404 can allow attackers to gain unauthorized access to the network devices, potentially leading to further exploitation and data breaches.