QID 43853

Date Published: 2021-09-07

QID 43853: Huawei Switch Information Exposure Vulnerability (Huawei-SA-20160112-01-Switch)

There is an information exposure vulnerability in Huawei Ethernet switch. When uploading files to some directory, the user needs to enter the username and password. However, the system does not mask passwords. As a result, the password entered is displayed in plain text, leading to password leaks. (Vulnerability ID: HWPSIRT-2015-08053)

On successful exploitation the password entered is displayed in plain text, leading to password leaks.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20160112-01-switch for updates and patch information.
    Vendor References

    CVEs related to QID 43853

    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20160112-01-switch Huawei VRP URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20160112-01-switch-en