CVE-2018-7958: High severity huawei espace 7950 firmware vulnerability
Published Nov 27, 2018
·Updated
There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS. Due to insufficient authentication, which may be exploited to intercept and tamper with the data information.
Affected Software
2 affected components
Huawei Espace 7950 Firmware=v200r003c30
Huawei eSpace 7950
Event History
Nov 27, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Huawei eSpace product vulnerability?
The vulnerability ID is CVE-2018-7958.
2
What is the severity rating of CVE-2018-7958?
The severity rating of CVE-2018-7958 is 7.4 (High).
3
Which Huawei eSpace product is affected by CVE-2018-7958?
Huawei eSpace 7950 Firmware v200r003c30 is affected by CVE-2018-7958.
4
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2018-7958 is CWE-287.
5
How can the anonymous TLS cipher suites supported vulnerability in Huawei eSpace product be exploited?
An unauthenticated, remote attacker can launch a man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS.