CVE-2015-2254
CRITICALHuawei OceanStor UDS Firmware < 100r002c01spc102 - Exposure of Sensitive Information via Patch Loading
Title source: llmDescription
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resulting in the deletion of directory files and compromise of system functions when loading a patch.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.huawei.com/en/psirt/security-advisories/hw-417839
Scores
CVSS v3
9.1
EPSS
0.0028
EPSS Percentile
51.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-200
Status
published
Products (1)
huawei/oceanstor_uds_firmware
< 100r002c01spc102
Published
Mar 13, 2019
Tracked Since
Feb 18, 2026