Описание
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
Ссылки
- Vendor Advisory
- Third Party AdvisoryURL Repurposed
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryURL Repurposed
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до v200r003b015d15sp00c983 (включая)
cpe:2.3:o:huawei:utps_firmware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.0042
Низкий
6.7 Medium
CVSS3
7.2 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 6.7
github
больше 3 лет назад
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
EPSS
Процентиль: 61%
0.0042
Низкий
6.7 Medium
CVSS3
7.2 High
CVSS2
Дефекты
CWE-264