First published: Wed Sep 07 2016(Updated: )
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei UMA Firmware | <=v200r001c00spc200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7108 has a high severity rating due to the potential for remote authenticated users to access MD5 hashes of arbitrary user passwords.
To fix CVE-2016-7108, it is recommended to upgrade to Huawei Unified Maintenance Audit version V200R001C00SPC200 or later.
CVE-2016-7108 affects users of Huawei Unified Maintenance Audit versions prior to V200R001C00SPC200.
CVE-2016-7108 is a vulnerability that allows remote authenticated users to exploit improper access controls to retrieve user password hashes.
CVE-2016-7108 was disclosed on August 24, 2016, as part of Huawei's security advisory.