Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20140707-01-STRUTS2
HistoryJul 07, 2014 - 12:00 a.m.

Security Advisory-Apache Struts2 vulnerability on Huawei multiple products

2014-07-0700:00:00
Huawei Technologies
www.huawei.com
69

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.97

Percentile

99.8%

Some versions of Apache Struts2 software used in Huawei devices have security vulnerabilities. A patch released for the software to fix vulnerabilities CVE-2014-0050 and CVE-2014-0094 has the risk of being bypassed. (Vulnerability ID: HWPSIRT-2014-0420)

This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-0116.

Affected configurations

Vulners
Node
huaweianyofficeMatchv200r002c10spc500
OR
huaweiespace_meetingMatchv100r001c00
OR
huaweieudemon8000e_firmwareMatchv200r001c00
OR
huaweix8_firmwareMatchv200r001c00
OR
huaweiusg9520Matchv200r001c00
OR
huaweiusg9560_firmwareMatchv200r001c00
OR
huaweiusg9580_firmwareMatchv200r001c00
OR
huaweiantiddos_8030_firmwareMatchv100r001c00
OR
huawei8060_firmwareMatchv100r001c00
OR
huawei8080_antiddos_1520_firmwareMatchv100r001c00
OR
huawei1550_firmwareMatchv100r001c00
OR
huaweiatlas_500_firmwareMatchv100r001c00
VendorProductVersionCPE
huaweianyofficev200r002c10spc500cpe:2.3:a:huawei:anyoffice:v200r002c10spc500:*:*:*:*:*:*:*
huaweiespace_meetingv100r001c00cpe:2.3:a:huawei:espace_meeting:v100r001c00:*:*:*:*:*:*:*
huaweieudemon8000e_firmwarev200r001c00cpe:2.3:o:huawei:eudemon8000e_firmware:v200r001c00:*:*:*:*:*:*:*
huaweix8_firmwarev200r001c00cpe:2.3:a:huawei:x8_firmware:v200r001c00:*:*:*:*:*:*:*
huaweiusg9520v200r001c00cpe:2.3:a:huawei:usg9520:v200r001c00:*:*:*:*:*:*:*
huaweiusg9560_firmwarev200r001c00cpe:2.3:o:huawei:usg9560_firmware:v200r001c00:*:*:*:*:*:*:*
huaweiusg9580_firmwarev200r001c00cpe:2.3:o:huawei:usg9580_firmware:v200r001c00:*:*:*:*:*:*:*
huaweiantiddos_8030_firmwarev100r001c00cpe:2.3:a:huawei:antiddos_8030_firmware:v100r001c00:*:*:*:*:*:*:*
huawei8060_firmwarev100r001c00cpe:2.3:a:huawei:8060_firmware:v100r001c00:*:*:*:*:*:*:*
huawei8080_antiddos_1520_firmwarev100r001c00cpe:2.3:a:huawei:8080_antiddos_1520_firmware:v100r001c00:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.97

Percentile

99.8%