First published: Wed Sep 07 2016(Updated: )
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei S12700 Firmware | =v200r005c00 | |
Huawei S12700 Firmware | ||
Huawei LSW S9700 firmware | =v200r003c00 | |
Huawei LSW S9700 firmware | =v200r005c00 | |
Huawei Campus LSW S9700 | ||
Huawei Campus S7700 firmware | =v200r003c00 | |
Huawei Campus S7700 firmware | =v200r005c00 | |
Huawei Campus S7700 | ||
Huawei Campus S9300 Firmware | =v200r003c00 | |
Huawei Campus S9300 Firmware | =v200r005c00 | |
Huawei Campus S9300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6670 is classified as a high severity vulnerability due to insufficient entropy in certificate generation leading to potential private key exposure.
To remediate CVE-2016-6670, upgrade the firmware to version V200R008C00SPC500 or later for affected Huawei devices.
CVE-2016-6670 affects Huawei S7700, S9300, S9700, and S12700 devices running software versions prior to V200R008C00SPC500.
Exploitation of CVE-2016-6670 may allow remote attackers to easily discover private keys from self-signed certificates.
No specific workarounds are available for CVE-2016-6670; updating to the recommended firmware version is necessary.