CVE-2016-8769

Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
Configurations

Configuration 1 (hide)

cpe:2.3:o:huawei:utps_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:00

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en - Vendor Advisory
References () http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/ - Third Party Advisory, URL Repurposed () http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/ - Third Party Advisory, URL Repurposed
References () http://www.securityfocus.com/bid/94403 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94403 - Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/40807/ - Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/40807/ - Third Party Advisory, VDB Entry

14 Feb 2024, 01:17

Type Values Removed Values Added
References (MISC) http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/ - Third Party Advisory (MISC) http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/ - Third Party Advisory, URL Repurposed

Information

Published : 2017-04-02 20:59

Updated : 2024-11-21 03:00


NVD link : CVE-2016-8769

Mitre link : CVE-2016-8769

CVE.ORG link : CVE-2016-8769


JSON object : View

Products Affected

huawei

  • utps_firmware
CWE
CWE-264

Permissions, Privileges, and Access Controls