First published: Sun Apr 02 2017(Updated: )
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Hisuite | =4.0.5.300_ove |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8273 has a moderate severity level due to its potential for exploitation through MITM attacks.
To fix CVE-2016-8273, upgrade to a version of Huawei HiSuite that utilizes secure HTTPS for software package downloads.
The risks associated with CVE-2016-8273 include the possibility of an attacker intercepting or replacing updates, leading to system compromise.
Huawei HiSuite version 4.0.5.300_OVE is the affected version for CVE-2016-8273.
It is not recommended to continue using Huawei HiSuite 4.0.5.300_OVE due to the identified security vulnerabilities.