CVE-2015-8673

UnknownEPSS 0.24%

Last modified

CVE-2015-8673 is a vulnerability of currently unknown severity. Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation.

Metrics

EPSS Probability
0.24%

14.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiTe30All versions
HuaweiTe40All versions
HuaweiTe50All versions
HuaweiTe60All versions
HuaweiTe60 Firmware<= v100r001c10b022

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-8673?
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation.
How severe is CVE-2015-8673?
Severity scoring for CVE-2015-8673 is pending analysis. The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2015-8673?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-8673?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST