9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
0.003 Low
EPSS
Percentile
71.5%
This security advisory (SA) describes the impact of DLL-Hijacking vulnerability discovered in website. (Vulnerability ID: HWPSIRT-2014-1046)
This vulnerability is referenced in this document as follows:
Any user in the system can modify the legitimate binary to any kind of malicious executable. If an attacker breakinto a low privilege account he could use this application to escalate his privileges.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8358.
The user could also place a malicious wintab32.dll file inside the “Mobile Partner” folder and perform DLL hijacking.
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-8359.
CPE | Name | Operator | Version |
---|---|---|---|
ec177 | eq | UTPS-V200R003B009D05SP03C1014 | |
ec176 | eq | UTPS-V200R003B009D05SP03C1014 | |
ec156 | eq | UTPS-V200R003B009D05SP03C1014 |
9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
7.8 High
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
0.003 Low
EPSS
Percentile
71.5%