CVE-2017-8156
medium
CVSS v3
6.8
CVSS v2
7.2
VIR risk
6.8
Description
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. Successful exploit could allow the attacker to take control over the outdoor unit.
Predictions
Exploit likelihood
67%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20170920-01-cpe-en
References
CWEs
CWE-306
Verify integrity in audit chain (admin only). AS-IS.