First published: Wed Nov 22 2017(Updated: )
VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Vcm5010 Firmware | <v100r002c50spc100 | |
Huawei Vcm5010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2736 has a moderate severity rating due to the potential for command injection attacks.
To fix CVE-2017-2736, upgrade the Huawei VCM5010 firmware to version V100R002C50SPC100 or later.
CVE-2017-2736 affects users of Huawei VCM5010 with firmware versions earlier than V100R002C50SPC100.
CVE-2017-2736 is a command injection vulnerability caused by insufficient validation of user input.
No, an authenticated attacker is required to exploit CVE-2017-2736.