CVE-2017-8138
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20170531-01-hedex-en
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| huawei | hedex_lite | {"endExcluding":"v200r006c00"} | v200r006c00 |
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.