Arbitrary File Download Vulnerability in HedEx by Huawei
CVE-2017-8136

5.5MEDIUM

Key Information:

Vendor

McAfee

Vendor
CVE Published:
22 November 2017

What is CVE-2017-8136?

HedEx by Huawei, prior to version V200R006C00, is susceptible to an arbitrary file download vulnerability. This security flaw enables attackers to exploit the system for unauthorized access, potentially allowing them to download sensitive files from the affected device. This can lead to significant information leakage, compromising the integrity and confidentiality of the system.

Affected Version(s)

HedEx Lite Earlier than V200R006C00 versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-8136 : Arbitrary File Download Vulnerability in HedEx by Huawei