CVE-2018-7959: Medium severity huawei espace 7950 firmware vulnerability
There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information leak.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-7959.
What is the severity of CVE-2018-7959?
The severity of CVE-2018-7959 is medium with a CVSS score of 5.9.
What is the affected software?
The affected software is Huawei eSpace 7950 Firmware version v200r003c30.
How does the vulnerability CVE-2018-7959 work?
The vulnerability CVE-2018-7959 allows an unauthenticated remote attacker to launch a man-in-the-middle attack and intercept and decrypt call information when SRTP is enabled for making a call.
How can CVE-2018-7959 be exploited?
The vulnerability CVE-2018-7959 can be exploited by an unauthenticated remote attacker by launching a man-in-the-middle attack.