ID

VAR-201511-0199


CVE

CVE-2015-8227


TITLE

Huawei VP9660 Remote Security Bypass Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2015-07799 // BID: 77559

DESCRIPTION

The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote administrators to obtain sensitive information or cause a denial of service via a crafted message. Huawei VP9660 is a multipoint controller for Huawei video conferencing systems. Huawei VP9660 is a new generation of professional full HD video conferencing terminal products from China Huawei. A remote security bypass vulnerability exists in Huawei VP9660. An attacker could exploit the vulnerability to bypass security restrictions and perform unauthorized operations. This may aid in further attacks

Trust: 3.06

sources: NVD: CVE-2015-8227 // JVNDB: JVNDB-2015-006026 // CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // BID: 77559 // VULHUB: VHN-86188

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 1.2

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799

AFFECTED PRODUCTS

vendor:huaweimodel:vp 9660scope:eqversion:v200r001c01

Trust: 1.6

vendor:huaweimodel:vp 9660scope:eqversion:v200r001c02

Trust: 1.6

vendor:huaweimodel:vp9660scope: - version: -

Trust: 1.4

vendor:huaweimodel:vp 9660scope:lteversion:v200r001c30

Trust: 1.0

vendor:huaweimodel:vp9660scope:ltversion:v200r001c30spc700

Trust: 0.8

vendor:huaweimodel:vp9660 <v200r001c30spc700scope: - version: -

Trust: 0.6

vendor:huaweimodel:vp 9660scope:eqversion:v200r001c30

Trust: 0.6

vendor:huaweimodel:vp9660 v200r001c30scope: - version: -

Trust: 0.3

vendor:huaweimodel:vp9660 v200r001c02scope: - version: -

Trust: 0.3

vendor:huaweimodel:vp9660 v200r001c01scope: - version: -

Trust: 0.3

vendor:huaweimodel:vp9660 v200r001c30spc700scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // BID: 77559 // JVNDB: JVNDB-2015-006026 // CNNVD: CNNVD-201511-391 // NVD: CVE-2015-8227

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-8227
value: HIGH

Trust: 1.0

NVD: CVE-2015-8227
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-07795
value: HIGH

Trust: 0.6

CNVD: CNVD-2015-07799
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201511-391
value: HIGH

Trust: 0.6

VULHUB: VHN-86188
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-8227
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:M/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-07795
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:M/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2015-07799
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-86188
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:M/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // VULHUB: VHN-86188 // JVNDB: JVNDB-2015-006026 // CNNVD: CNNVD-201511-391 // NVD: CVE-2015-8227

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-86188 // JVNDB: JVNDB-2015-006026 // NVD: CVE-2015-8227

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201511-391

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201511-391

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006026

PATCH

title:Huawei-SA-20151111-01-VP9660url:http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-461216.htm

Trust: 0.8

title:Huawei VP9660 Information Disclosure Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/67213

Trust: 0.6

title:Huawei VP9660 Remote Security Bypass Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/67107

Trust: 0.6

title:Huawei VP9660 Multi-point control unit input verification vulnerability repair measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58839

Trust: 0.6

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // JVNDB: JVNDB-2015-006026 // CNNVD: CNNVD-201511-391

EXTERNAL IDS

db:NVDid:CVE-2015-8227

Trust: 3.1

db:BIDid:77559

Trust: 1.5

db:JVNDBid:JVNDB-2015-006026

Trust: 0.8

db:CNNVDid:CNNVD-201511-391

Trust: 0.7

db:CNVDid:CNVD-2015-07795

Trust: 0.6

db:CNVDid:CNVD-2015-07799

Trust: 0.6

db:NSFOCUSid:31617

Trust: 0.6

db:SEEBUGid:SSVID-89930

Trust: 0.1

db:VULHUBid:VHN-86188

Trust: 0.1

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // VULHUB: VHN-86188 // BID: 77559 // JVNDB: JVNDB-2015-006026 // CNNVD: CNNVD-201511-391 // NVD: CVE-2015-8227

REFERENCES

url:http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-461216.htm

Trust: 1.7

url:http://www.securityfocus.com/bid/77559

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-8227

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-8227

Trust: 0.8

url:http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htm

Trust: 0.6

url:http://www.nsfocus.net/vulndb/31617

Trust: 0.6

url:http://www.huawei.com

Trust: 0.3

url:http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/archive/hw-461216.htm

Trust: 0.3

sources: CNVD: CNVD-2015-07795 // CNVD: CNVD-2015-07799 // VULHUB: VHN-86188 // BID: 77559 // JVNDB: JVNDB-2015-006026 // CNNVD: CNNVD-201511-391 // NVD: CVE-2015-8227

CREDITS

Huawei

Trust: 0.9

sources: BID: 77559 // CNNVD: CNNVD-201511-391

SOURCES

db:CNVDid:CNVD-2015-07795
db:CNVDid:CNVD-2015-07799
db:VULHUBid:VHN-86188
db:BIDid:77559
db:JVNDBid:JVNDB-2015-006026
db:CNNVDid:CNNVD-201511-391
db:NVDid:CVE-2015-8227

LAST UPDATE DATE

2024-11-23T21:54:47.877000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-07795date:2015-11-26T00:00:00
db:CNVDid:CNVD-2015-07799date:2015-11-26T00:00:00
db:VULHUBid:VHN-86188date:2016-09-13T00:00:00
db:BIDid:77559date:2015-11-11T00:00:00
db:JVNDBid:JVNDB-2015-006026date:2015-11-26T00:00:00
db:CNNVDid:CNNVD-201511-391date:2015-11-27T00:00:00
db:NVDid:CVE-2015-8227date:2024-11-21T02:38:07.770

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-07795date:2015-11-26T00:00:00
db:CNVDid:CNVD-2015-07799date:2015-11-26T00:00:00
db:VULHUBid:VHN-86188date:2015-11-24T00:00:00
db:BIDid:77559date:2015-11-11T00:00:00
db:JVNDBid:JVNDB-2015-006026date:2015-11-26T00:00:00
db:CNNVDid:CNNVD-201511-391date:2015-11-23T00:00:00
db:NVDid:CVE-2015-8227date:2015-11-24T20:59:17.393