4.9

CVE-2015-8086

Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.

Data is provided by the National Vulnerability Database (NVD)
HuaweiQuidway S5300 Firmware Versionv200r001c00spc300
   HuaweiQuidway S5300 Version-
HuaweiQuidway S9300 Firmware Versionv200r001c00spc300
   HuaweiQuidway S9300 Version-
HuaweiQuidway S9300 Firmware Versionv200r002c00spc100
   HuaweiQuidway S9300 Version-
HuaweiQuidway S9300 Firmware Versionv200r003c00spc500
   HuaweiQuidway S9300 Version-
HuaweiS5700 Firmware Versionv200r001c00
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r002c00
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r003c00
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r005c00
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r006c00
   HuaweiS5700 Version-
HuaweiS12700 Firmware Versionv200r005c00
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r006c00
   HuaweiS12700 Version-
HuaweiAr Firmware Versionv200r001
   HuaweiAr Version-
HuaweiAr Firmware Versionv200r002
   HuaweiAr Version-
HuaweiAr Firmware Versionv200r003
   HuaweiAr Version-
HuaweiAr Firmware Versionv200r005c10
   HuaweiAr Version-
HuaweiAr Firmware Versionv200r005c20
   HuaweiAr Version-
HuaweiAr Firmware Versionv200r005c30
   HuaweiAr Version-
HuaweiS5300 Firmware Versionv200r002c00
   HuaweiS5300 Version-
HuaweiS5300 Firmware Versionv200r005c00spc500
   HuaweiS5300 Version-
HuaweiS5300 Firmware Versionv200r006c00spc500
   HuaweiS5300 Version-
HuaweiS9300 Firmware Versionv200r005c00spc300
   HuaweiS9300 Version-
HuaweiS9300 Firmware Versionv200r006c00spc500
   HuaweiS9300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.03% 0.043
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.