Lucene search

K
cve[email protected]CVE-2014-8331
HistoryOct 20, 2014 - 4:55 p.m.

CVE-2014-8331

2014-10-2016:55:09
CWE-352
web.nvd.nist.gov
14
cve-2014-8331
security vulnerability
csrf
cross-site request forgery
huawei hilink e3236
huawei hilink e3276

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.6%

Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B146D41SP00C00 and E3236sWebUI-V100R007B100D03SP01C03 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) use device functions.

Affected configurations

NVD
Node
huaweie3236_firmwareMatche3236s-2tcpu-22.146.29.00.00
OR
huaweie3236_firmwareMatchwebui-13.100.10.00.03
OR
huaweie3276_firmwareMatche3276s-150tcpu-22.265.03.00.00
OR
huaweie3276_firmwareMatchwebui-13.100.09.00.03

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.6%

Related for CVE-2014-8331