huawei.comConfirmation
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en CVE-2016-8769
MEDIUM
Huawei UTPS - Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-8769 has a selected CVSS score of 6.7 (medium); EIP currently links 1 catalogued exploit.
Description
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | earlier than UTPS-V200R003B015D16SPC00C983 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBHuawei UTPS - Unquoted Service Path Privilege EscalationExploitDB exploitby Dhruv ShahNot analyzed1 file
References
5security-geek.in
http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles 94403vdb entry
http://www.securityfocus.com/bid/94403 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-8769 40807exploit
https://www.exploit-db.com/exploits/40807