CVE-2022-48615

An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.
References
Link Resource
https://wr3nchsr.github.io/huawei-netengine-ar617vw-auth-root-rce/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:ar617vw_firmware:v300r21c00spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar617vw:-:*:*:*:*:*:*:*

History

15 Dec 2023, 15:02

Type Values Removed Values Added
References () https://wr3nchsr.github.io/huawei-netengine-ar617vw-auth-root-rce/ - () https://wr3nchsr.github.io/huawei-netengine-ar617vw-auth-root-rce/ - Exploit, Third Party Advisory
CPE cpe:2.3:o:huawei:ar617vw_firmware:v300r21c00spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar617vw:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : 7.1
CWE NVD-CWE-Other
First Time Huawei
Huawei ar617vw Firmware
Huawei ar617vw

12 Dec 2023, 13:43

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de control de acceso inadecuado en un producto de comunicación de datos de Huawei. Los atacantes pueden aprovechar esta vulnerabilidad para obtener información parcial del dispositivo.

12 Dec 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 08:15

Updated : 2023-12-15 15:02


NVD link : CVE-2022-48615

Mitre link : CVE-2022-48615

CVE.ORG link : CVE-2022-48615


JSON object : View

Products Affected

huawei

  • ar617vw
  • ar617vw_firmware
CWE
NVD-CWE-Other CWE-284

Improper Access Control