CVE-2016-6838
Last modified
CVE-2016-6838 is a vulnerability of currently unknown severity. Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Rh1288 V3 Server Firmware | v100r003c00 |
| Huawei | Rh2288 V3 Server Firmware | v100r003c00 |
| Huawei | X6800 V3 Server Firmware | v100r003c00 |
| Huawei | Xh620 V3 Server Firmware | v100r003c00 |
| Huawei | Ch121 V3 Server Firmware | v100r001c00 |
| Huawei | Ch140 V3 Server Firmware | v100r001c00 |
| Huawei | Ch220 V3 Server Firmware | v100r001c00 |
| Huawei | Ch222 V3 Server Firmware | v100r001c00 |
| Huawei | Ch226 V3 Server Firmware | v100r001c00 |
References
- http://www.securityfocus.com/bid/92503Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92503Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6838?
How severe is CVE-2016-6838?
How do I fix CVE-2016-6838?
Are you affected by CVE-2016-6838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
