7.5

CVE-2012-6571

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

Data is provided by the National Vulnerability Database (NVD)
HuaweiAr 18-1x Version <= r0130
HuaweiAr 18-2x Version <= r1712
HuaweiAr 18-3x Version <= r0118
HuaweiS2000 Versionr6305
HuaweiS2300 Versionr6305
HuaweiS2700 Versionr6305
HuaweiS3000 Versionr6305
HuaweiS3300 Versionr6305
HuaweiS3300hi Versionr6305
HuaweiS3500 Versionr6305
HuaweiS3700 Versionr6305
HuaweiS3900 Versionr6305
HuaweiS5100 Versionr6305
HuaweiS5600 Versionr6305
HuaweiS7800 Versionr6305
HuaweiS8500 Versionr1631
HuaweiS8500 Versionr1632
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.386
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P