CVE-2016-7109
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-uma-en
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| huawei | uma | {"endIncluding":"v200r001c00spc100"} | |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.