CVE-2017-2738
- EPSS 1.25%
- Published 22.11.2017 19:29:02
- Last modified 20.04.2025 01:37:25
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of authentication for accessing web pages. An unauthenticated attacker could bypass the authentication ...
CVE-2017-2736
- EPSS 1.06%
- Published 22.11.2017 19:29:01
- Last modified 20.04.2025 01:37:25
VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.
CVE-2017-2737
- EPSS 0.25%
- Published 22.11.2017 19:29:01
- Last modified 20.04.2025 01:37:25
VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.
CVE-2015-8332
- EPSS 0.25%
- Published 28.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a craft...