CVE-2017-15328

Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exploitation may cause information leak.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:hg8245h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hg8245h:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:14

Type Values Removed Values Added
References () http://support.huawei.com/carrier/docview%21docview?nid=DOC1000441394&path=PBI1-7275726/PBI1-7275742/PBI1-7912539/PBI1-22318696/PBI1-8952133/PBI1-8957546/PBI1-22412232/PBI1-22412234/PBI1-22807623 - () http://support.huawei.com/carrier/docview%21docview?nid=DOC1000441394&path=PBI1-7275726/PBI1-7275742/PBI1-7912539/PBI1-22318696/PBI1-8952133/PBI1-8957546/PBI1-22412232/PBI1-22412234/PBI1-22807623 -
References () https://hacked0x90.wordpress.com/2017/11/30/hg8245h-authentication-bypass/ - Third Party Advisory () https://hacked0x90.wordpress.com/2017/11/30/hg8245h-authentication-bypass/ - Third Party Advisory

07 Nov 2023, 02:39

Type Values Removed Values Added
References
  • {'url': 'http://support.huawei.com/carrier/docview!docview?nid=DOC1000441394&path=PBI1-7275726/PBI1-7275742/PBI1-7912539/PBI1-22318696/PBI1-8952133/PBI1-8957546/PBI1-22412232/PBI1-22412234/PBI1-22807623', 'name': 'http://support.huawei.com/carrier/docview!docview?nid=DOC1000441394&path=PBI1-7275726/PBI1-7275742/PBI1-7912539/PBI1-22318696/PBI1-8952133/PBI1-8957546/PBI1-22412232/PBI1-22412234/PBI1-22807623', 'tags': [], 'refsource': 'MISC'}
  • () http://support.huawei.com/carrier/docview%21docview?nid=DOC1000441394&path=PBI1-7275726/PBI1-7275742/PBI1-7912539/PBI1-22318696/PBI1-8952133/PBI1-8957546/PBI1-22412232/PBI1-22412234/PBI1-22807623 -

Information

Published : 2017-12-22 17:29

Updated : 2024-11-21 03:14


NVD link : CVE-2017-15328

Mitre link : CVE-2017-15328

CVE.ORG link : CVE-2017-15328


JSON object : View

Products Affected

huawei

  • hg8245h
  • hg8245h_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor