CVE-2016-7108: Infoleak
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7108?
CVE-2016-7108 has a high severity rating due to the potential for remote authenticated users to access MD5 hashes of arbitrary user passwords.
How do I fix CVE-2016-7108?
To fix CVE-2016-7108, it is recommended to upgrade to Huawei Unified Maintenance Audit version V200R001C00SPC200 or later.
Who is affected by CVE-2016-7108?
CVE-2016-7108 affects users of Huawei Unified Maintenance Audit versions prior to V200R001C00SPC200.
What type of vulnerability is CVE-2016-7108?
CVE-2016-7108 is a vulnerability that allows remote authenticated users to exploit improper access controls to retrieve user password hashes.
When was CVE-2016-7108 disclosed?
CVE-2016-7108 was disclosed on August 24, 2016, as part of Huawei's security advisory.