Password Change Vulnerability in Huawei Multimedia Video Conferencing Endpoints
CVE-2015-8673

6.8MEDIUM

Key Information:

Vendor
Huawei
Status
Te50
Te40
Te60
Te30
Vendor
CVE Published:
12 January 2016

Summary

Huawei's TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints have a security flaw that allows an attacker with physical access to change the Debug account password without needing to know the old password. This vulnerability arises when devices are left unattended, making it possible for unauthorized individuals to gain access and alter security settings.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.