CVE-2016-6827: Infoleak
Published Sep 26, 2016
·Updated
Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
huawei FusionCompute<=v100r003c10
Event History
Sep 26, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6827?
CVE-2016-6827 is considered a critical vulnerability due to the exposure of sensitive AES keys.
2
How do I fix CVE-2016-6827?
To mitigate CVE-2016-6827, upgrade your Huawei FusionCompute to version V100R005C10CP7002 or later.
3
Who is affected by CVE-2016-6827?
CVE-2016-6827 affects users of Huawei FusionCompute versions up to V100R003C10.
4
What information is exposed by CVE-2016-6827?
CVE-2016-6827 allows remote authenticated users to obtain sensitive AES keys stored in cleartext.
5
What are the potential risks of CVE-2016-6827?
The risks include unauthorized access to encrypted data and potential compromise of systems that rely on the exposed AES keys.