huawei e585u-82 Security Vulnerabilities

3 Vulnerabilities
Description

The Huawei E585 device allows remote attackers to cause a denial of service (NULL pointer dereference and device outage) via crafted HTTP requests, as demonstrated by unspecified vulnerability-scanning software.~Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference'

Impacted versions: -

Base Score: 6.1, Severity: MEDIUM, ID: CVE-2012-5970, Last Modified: 2013-01-29T05:00:00Z

References

Vendor Advisory US Government Resource

The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.

Impacted versions: -

Base Score: 4.8, Severity: MEDIUM, ID: CVE-2012-5968, Last Modified: 2013-01-29T05:00:00Z

References

Vendor Advisory US Government Resource

Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (dot dot) in the req_page parameter to en/sms.cgi.

Impacted versions: -

Base Score: 4.8, Severity: MEDIUM, ID: CVE-2012-5969, Last Modified: 2012-12-19T11:55:00Z

References

Vendor Advisory US Government Resource
Free Home-Networking Courses, tutorials and security checklists

USAGE: Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.