7.8

CVE-2015-2800

The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S9700 with software before V200R001SPH015 allows remote attackers to cause a denial of service (device restart) via vectors involving authentication, which trigger an array access violation.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HuaweiS5700 Firmware Version <= v200r001c00spc300
   HuaweiCampus S5700 Version-
HuaweiS5300 Firmware Version <= v200r001c00spc300
   HuaweiCampus S5300 Version-
HuaweiS6300 Firmware Version <= v200r001c00spc300
   HuaweiCampus S6300 Version-
HuaweiS6700 Firmware Version <= v200r001c00spc300
   HuaweiCampus S6700 Version-
HuaweiS7700 Firmware Version <= v200r001c00spc300
   HuaweiCampus S7700 Version-
HuaweiS9300 Firmware Version <= v200r001c00spc300
   HuaweiCampus S9300 Version-
HuaweiS9700 Firmware Version <= v200r001c00spc300
   HuaweiCampus S9700 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.8% 0.849
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.