CVE-2016-6838
Last modified
CVE-2016-6838 is a vulnerability of currently unknown severity. Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Rh1288 V3 Server Firmware | v100r003c00 |
| Huawei | Rh2288 V3 Server Firmware | v100r003c00 |
| Huawei | X6800 V3 Server Firmware | v100r003c00 |
| Huawei | Xh620 V3 Server Firmware | v100r003c00 |
| Huawei | Ch121 V3 Server Firmware | v100r001c00 |
| Huawei | Ch140 V3 Server Firmware | v100r001c00 |
| Huawei | Ch220 V3 Server Firmware | v100r001c00 |
| Huawei | Ch222 V3 Server Firmware | v100r001c00 |
| Huawei | Ch226 V3 Server Firmware | v100r001c00 |
References
- http://www.securityfocus.com/bid/92503Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92503Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6838?
How severe is CVE-2016-6838?
How do I fix CVE-2016-6838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-6832Heap-based buffer overflow in the ff_audio_resample function…
- CVE-2016-6833Use-after-free vulnerability in the vmxnet3_io_bar0_write fu…4.4
- CVE-2016-6834The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx…4.4
- CVE-2016-6835The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx…6
- CVE-2016-6836The vmxnet3_complete_packet function in hw/net/vmxnet3.c in …6
- CVE-2016-6837Cross-site scripting (XSS) vulnerability in MantisBT Filter …
- CVE-2016-6839CRLF injection vulnerability in Huawei FusionAccess before V…
- CVE-2016-6840Cross-site scripting (XSS) vulnerability in the management i…
- CVE-2016-6842An issue was discovered in Open-Xchange OX App Suite before …
- CVE-2016-6843An issue was discovered in Open-Xchange OX App Suite before …
- CVE-2016-6844An issue was discovered in Open-Xchange OX App Suite before …
- CVE-2016-6845An issue was discovered in Open-Xchange OX App Suite before …
Are you affected by CVE-2016-6838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
