CVE-2016-8789
medium
CVSS v3
6.1
CVSS v2
4.3
VIR risk
6.1
Description
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
Predictions
Exploit likelihood
71%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161130-01-espace-en
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.