First published: Tue Nov 27 2018(Updated: )
There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Espace 7950 Firmware | =v200r003c30 | |
Huawei eSpace 7950 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7959.
The severity of CVE-2018-7959 is medium with a CVSS score of 5.9.
The affected software is Huawei eSpace 7950 Firmware version v200r003c30.
The vulnerability CVE-2018-7959 allows an unauthenticated remote attacker to launch a man-in-the-middle attack and intercept and decrypt call information when SRTP is enabled for making a call.
The vulnerability CVE-2018-7959 can be exploited by an unauthenticated remote attacker by launching a man-in-the-middle attack.