First published: Mon Sep 26 2016(Updated: )
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Fusioncompute Firmware | <=v100r003c10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6827 is considered a critical vulnerability due to the exposure of sensitive AES keys.
To mitigate CVE-2016-6827, upgrade your Huawei FusionCompute to version V100R005C10CP7002 or later.
CVE-2016-6827 affects users of Huawei FusionCompute versions up to V100R003C10.
CVE-2016-6827 allows remote authenticated users to obtain sensitive AES keys stored in cleartext.
The risks include unauthorized access to encrypted data and potential compromise of systems that rely on the exposed AES keys.