First published: Wed Nov 22 2017(Updated: )
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Hedex Lite | <v200r006c00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8138 is classified as a critical vulnerability due to its potential to allow an attacker to exploit CSRF.
To fix CVE-2017-8138, upgrade to Huawei Hedex Lite version V200R006C00 or later.
CVE-2017-8138 is a cross-site request forgery (CSRF) vulnerability.
An attacker could trick users into accessing malicious websites, potentially tampering with configurations and disrupting services.
Versions of HedEx earlier than V200R006C00 are affected by CVE-2017-8138.