Release date:
Updated on:
Affected Systems:
Huawei Secospace VSM V200R002C00SPC200
Huawei Secospace VSM V200R002C00SPC100
Huawei Secospace VSM V200R002C00
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58869
Huawei VSM is a unified security service management system.
When a user of the default user group logs on to the system to modify the Default User Group permission configuration, Huawei VSM has an error while verifying the user account. Attackers can exploit this vulnerability to improve the permissions of the default user group. The vendor has released VSM V200R002C00SPC300 to fix this vulnerability.
<* Source: vendor
Link: http://secunia.com/advisories/52891/
Http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-258449.htm
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Optimizes the VSM authentication policy to prevent elevation of permissions.
Vendor patch:
Huawei
------
Huawei has released a Security Bulletin (hw-258449) and patches for this:
Hw-258449: Security Advisory-Huawei VSM Default User Groups 'privilege Escalation
Link: http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-258449.htm
Patch download: http://support.huawei.com/enterprise/softdownload.action? IdAbsPath = fixnode01 % 7C7919710% 7C9856717% 7C7923123% percent % Percent & pid = 8577742 & vrc = 8616279% percent % Percent & show = showVDetail & tab = bz & bz_vr = 8616281 = & nbz_vr = null