First published: Sun Apr 02 2017(Updated: )
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei eSpace Integrated Access Device | =v300r001c03 | |
Huawei eSpace Integrated Access Device | =v300r001c04 | |
Huawei eSpace Integrated Access Device | =v300r001c06 | |
Huawei eSpace Integrated Access Device | =v300r001c07 | |
Huawei eSpace Integrated Access Device | =v300r001c20 | |
Huawei eSpace Integrated Access Device |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8789 is considered a medium severity vulnerability due to its potential for user information theft and session hijacking.
To fix CVE-2016-8789, update your Huawei eSpace Integrated Access Device firmware to the latest version provided by Huawei.
CVE-2016-8789 affects Huawei eSpace Integrated Access Device firmware versions V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07.
CVE-2016-8789 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2016-8789 can lead to data loss by allowing attackers to obtain sensitive user information.