Cross-Site Scripting Vulnerability in Huawei UMA Software
CVE-2017-8125

6.1MEDIUM

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
22 November 2017

Summary

The UMA software developed by Huawei versions V200R001 and V300R001 is susceptible to a cross-site scripting (XSS) vulnerability stemming from inadequate input validation. This security flaw allows malicious actors to craft harmful links or scripts, potentially leading to XSS attacks, which can compromise user data and application integrity. Users of these versions are advised to apply necessary security patches and updates provided by Huawei to mitigate the risk.

Affected Version(s)

UMA V200R001 and V300R001

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.