CVE-2016-6670: Infoleak
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6670?
CVE-2016-6670 is classified as a high severity vulnerability due to insufficient entropy in certificate generation leading to potential private key exposure.
How do I fix CVE-2016-6670?
To remediate CVE-2016-6670, upgrade the firmware to version V200R008C00SPC500 or later for affected Huawei devices.
Which devices are affected by CVE-2016-6670?
CVE-2016-6670 affects Huawei S7700, S9300, S9700, and S12700 devices running software versions prior to V200R008C00SPC500.
What is the impact of exploiting CVE-2016-6670?
Exploitation of CVE-2016-6670 may allow remote attackers to easily discover private keys from self-signed certificates.
Is there a workaround for CVE-2016-6670?
No specific workarounds are available for CVE-2016-6670; updating to the recommended firmware version is necessary.