CVE-2017-2737
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170329-01-vcm-en
References
CWEs
CWE-434
Verify integrity in audit chain (admin only). AS-IS.