CVE-2017-8128: Input Validation
Published Nov 22, 2017
·Updated
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Affected Software
2 affected components
huawei UMA=v200r001
huawei UMA=v300r001
Event History
Nov 22, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8128?
CVE-2017-8128 has a high severity rating due to the potential for privilege escalation.
2
How do I fix CVE-2017-8128?
To fix CVE-2017-8128, update to the latest version of Huaweis UMA software that addresses this vulnerability.
3
What versions of Huawei UMA are affected by CVE-2017-8128?
CVE-2017-8128 affects Huawei UMA versions V200R001 and V300R001.
4
What can an attacker do with CVE-2017-8128?
An attacker exploiting CVE-2017-8128 could gain elevated privileges on the affected system.
5
Is there a workaround for CVE-2017-8128?
Currently, the only reliable mitigation for CVE-2017-8128 is to apply the software update provided by Huawei.