CVE-2016-8754: High severity huawei oceanstor 5600 firmware vulnerability
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8754?
CVE-2016-8754 is considered a critical vulnerability due to the potential for unauthorized SSH access through hardcoded keys.
How do I fix CVE-2016-8754?
To mitigate CVE-2016-8754, update the Huawei OceanStor 5600 V3 firmware to a version that does not use hardcoded SSH keys.
What devices are affected by CVE-2016-8754?
CVE-2016-8754 affects the Huawei OceanStor 5600 V3 firmware version v300r003c00.
Can an attacker exploit CVE-2016-8754 remotely?
Yes, an attacker can exploit CVE-2016-8754 remotely by using the hardcoded SSH keys for unauthorized access.
Is CVE-2016-8754 specific to certain firmware versions?
CVE-2016-8754 specifically affects the Huawei OceanStor 5600 V3 firmware v300r003c00 and is not applicable to all versions.