First published: Wed Sep 07 2016(Updated: )
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei RH1288 V3 Firmware | =v100r003c00 | |
Huawei RH1288 V3 Firmware | =v100r003c00 | |
Huawei Rh2288h V3 Server Firmware | =v100r003c00 | |
Huawei Xh620 V3 Server Firmware | =v100r003c00 | |
Huawei Xh622 V3 Server Firmware | =v100r003c00 | |
Huawei Xh628 V3 Server Firmware | =v100r003c00 | |
Huawei RH1288 V3 | ||
Huawei Fusionserver Rh2288 V3 | ||
Huawei Fusionserver RH2288H V3 | ||
Huawei Xh620 V3 Server | ||
Huawei Xh622 V3 Server | ||
Huawei Fusionserver Xh628 V3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6825 has a medium severity rating, allowing remote attackers to gain unauthorized information.
To remediate CVE-2016-6825, update the affected Huawei server firmware to the specified versions or later.
CVE-2016-6825 affects Huawei RH1288 V3, RH2288 V3, RH2288H V3, XH620 V3, XH622 V3, and XH628 V3 servers.
CVE-2016-6825 can be exploited by remote attackers to obtain sensitive information.
CVE-2016-6825 was publicly disclosed in August 2016.