ID

VAR-201406-0321


CVE

CVE-2014-2946


TITLE

Huawei E303 contains a cross-site request forgery vulnerability

Trust: 0.8

sources: CERT/CC: VU#325636

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document. Huawei Provided by E303 The cross-site request forgery (CWE-352) Vulnerabilities exist. CWE-352: Cross-Site Request Forgery (CSRF) http://cwe.mitre.org/data/definitions/352.htmlUnintentional user access by accessing a specially crafted page SMS A message may be sent. Huawei E303 is a 3G Internet access device. Huawei E303 Router is prone to a cross-site request-forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks. Huawei E303 Router running firmware versions CH2E303SM is vulnerable; other versions may also be affected. Huawei E303 modems is a wireless broadband modem product of China Huawei (Huawei)

Trust: 3.24

sources: NVD: CVE-2014-2946 // CERT/CC: VU#325636 // JVNDB: JVNDB-2014-002685 // CNVD: CNVD-2014-03465 // BID: 67747 // VULHUB: VHN-70885

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03465

AFFECTED PRODUCTS

vendor:huaweimodel:webuiscope:eqversion:11.010.06.01.858

Trust: 2.4

vendor:huaweimodel:e303 modemscope:eqversion:22.157.18.00.858

Trust: 1.6

vendor:huaweimodel:e303scope: - version: -

Trust: 1.4

vendor:huaweimodel:e303 modemscope:eqversion:ch2e303sm

Trust: 1.0

vendor:huaweimodel: - scope: - version: -

Trust: 0.8

vendor:huaweimodel:e303scope:eqversion:22.157.18.00.858

Trust: 0.8

sources: CERT/CC: VU#325636 // CNVD: CNVD-2014-03465 // JVNDB: JVNDB-2014-002685 // CNNVD: CNNVD-201406-021 // NVD: CVE-2014-2946

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2946
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2946
value: MEDIUM

Trust: 0.8

IPA: JVNDB-2014-002685
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-03465
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201406-021
value: MEDIUM

Trust: 0.6

VULHUB: VHN-70885
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2946
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: CVE-2014-2946
severity: MEDIUM
baseScore: 4.3
vectorString: NONE
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

IPA: JVNDB-2014-002685
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2014-03465
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-70885
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#325636 // CNVD: CNVD-2014-03465 // VULHUB: VHN-70885 // JVNDB: JVNDB-2014-002685 // CNNVD: CNNVD-201406-021 // NVD: CVE-2014-2946

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-70885 // JVNDB: JVNDB-2014-002685 // NVD: CVE-2014-2946

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201406-021

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201406-021

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002685

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#325636 // VULHUB: VHN-70885

PATCH

title:E303 Specificationsurl:http://consumer.huawei.com/en/mobile-broadband/data-card/tech-specs/e303-en.htm

Trust: 0.8

sources: JVNDB: JVNDB-2014-002685

EXTERNAL IDS

db:NVDid:CVE-2014-2946

Trust: 4.2

db:CERT/CCid:VU#325636

Trust: 3.9

db:SECUNIAid:58992

Trust: 1.1

db:BIDid:67747

Trust: 1.0

db:JVNid:JVNVU96299627

Trust: 0.8

db:JVNDBid:JVNDB-2014-002685

Trust: 0.8

db:CNVDid:CNVD-2014-03465

Trust: 0.6

db:CNNVDid:CNNVD-201406-021

Trust: 0.6

db:EXPLOIT-DBid:39209

Trust: 0.1

db:VULHUBid:VHN-70885

Trust: 0.1

sources: CERT/CC: VU#325636 // CNVD: CNVD-2014-03465 // VULHUB: VHN-70885 // BID: 67747 // JVNDB: JVNDB-2014-002685 // CNNVD: CNNVD-201406-021 // NVD: CVE-2014-2946

REFERENCES

url:http://www.kb.cert.org/vuls/id/325636

Trust: 3.1

url:http://b.fl7.de/2014/05/huawei-e303-sms-vulnerability-cve-2014-2946.html

Trust: 1.9

url:http://secunia.com/advisories/58992

Trust: 1.1

url:http://www.huawei.com

Trust: 0.8

url:http://consumer.huawei.com/en/mobile-broadband/data-card/tech-specs/e303-en.htm

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2946

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96299627/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2946

Trust: 0.8

sources: CERT/CC: VU#325636 // CNVD: CNVD-2014-03465 // VULHUB: VHN-70885 // JVNDB: JVNDB-2014-002685 // CNNVD: CNNVD-201406-021 // NVD: CVE-2014-2946

CREDITS

Benjamin Daniel Mussler

Trust: 0.3

sources: BID: 67747

SOURCES

db:CERT/CCid:VU#325636
db:CNVDid:CNVD-2014-03465
db:VULHUBid:VHN-70885
db:BIDid:67747
db:JVNDBid:JVNDB-2014-002685
db:CNNVDid:CNNVD-201406-021
db:NVDid:CVE-2014-2946

LAST UPDATE DATE

2024-11-23T21:45:03.481000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#325636date:2014-06-05T00:00:00
db:CNVDid:CNVD-2014-03465date:2014-06-06T00:00:00
db:VULHUBid:VHN-70885date:2014-06-18T00:00:00
db:BIDid:67747date:2014-05-30T00:00:00
db:JVNDBid:JVNDB-2014-002685date:2014-06-04T00:00:00
db:CNNVDid:CNNVD-201406-021date:2014-06-05T00:00:00
db:NVDid:CVE-2014-2946date:2024-11-21T02:07:13.587

SOURCES RELEASE DATE

db:CERT/CCid:VU#325636date:2014-05-30T00:00:00
db:CNVDid:CNVD-2014-03465date:2014-06-05T00:00:00
db:VULHUBid:VHN-70885date:2014-06-02T00:00:00
db:BIDid:67747date:2014-05-30T00:00:00
db:JVNDBid:JVNDB-2014-002685date:2014-06-02T00:00:00
db:CNNVDid:CNNVD-201406-021date:2014-06-05T00:00:00
db:NVDid:CVE-2014-2946date:2014-06-02T19:55:03.440