Lucene search

K
cveHuaweiCVE-2018-7976
HistoryJun 01, 2018 - 2:29 p.m.

CVE-2018-7976

2018-06-0114:29:00
CWE-79
huawei
web.nvd.nist.gov
27
huawei
espace desktop
xss
vulnerability
cve-2018-7976
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

28.6%

There is a stored cross-site scripting (XSS) vulnerability in Huawei eSpace Desktop V300R001C00 and V300R001C50 version. Due to the insufficient validation of the input, an authenticated, remote attacker could exploit this vulnerability to send abnormal messages to the system and perform a XSS attack. A successful exploit could cause the eSpace Desktop to hang up, and the function will restore to normal after restarting the eSpace Desktop.

Affected configurations

Nvd
Vulners
Node
huaweiespace_desktopMatch300r001c00
OR
huaweiespace_desktopMatch300r001c50
VendorProductVersionCPE
huaweiespace_desktop300r001c00cpe:2.3:a:huawei:espace_desktop:300r001c00:*:*:*:*:*:*:*
huaweiespace_desktop300r001c50cpe:2.3:a:huawei:espace_desktop:300r001c50:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "eSpace Desktop",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "V300R001C00"
      },
      {
        "status": "affected",
        "version": "V300R001C50"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

28.6%

Related for CVE-2018-7976