First published: Sun Apr 02 2017(Updated: )
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei OceanStor 5600 firmware | =v300r003c00 | |
Huawei OceanStor S5600T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8754 is considered a critical vulnerability due to the potential for unauthorized SSH access through hardcoded keys.
To mitigate CVE-2016-8754, update the Huawei OceanStor 5600 V3 firmware to a version that does not use hardcoded SSH keys.
CVE-2016-8754 affects the Huawei OceanStor 5600 V3 firmware version v300r003c00.
Yes, an attacker can exploit CVE-2016-8754 remotely by using the hardcoded SSH keys for unauthorized access.
CVE-2016-8754 specifically affects the Huawei OceanStor 5600 V3 firmware v300r003c00 and is not applicable to all versions.