Multiple security vulnerabilities in Huawei ME906 (CVE-2015-5368)
Multiple security vulnerabilities in Huawei ME906 (CVE-2015-5368)
Release date:
Updated on:
Affected Systems:
Huawei ME906
Description:
Bugtraq id: 76176
CVE (CAN) ID: CVE-2015-5368
ME906 is a 4G access module product for Huawei's mobile Internet access. It supports LTE, WCDMA, EVDO, and GSM.
The Huawei ME906 module uses insecure CRC16 for upgrade checks. Attackers can exploit this vulnerability to perform unauthorized operations and bypass certain security restrictions.
<* Source: Mickey Shkatov
Jesse Michael
Link: Security_Advisory-Two Security Vulnerabilities in the ME906 Wireless Module-Huawei PSIRT.html
*>
Suggestion:
Vendor patch:
Huawei
------
Huawei has released a Security Bulletin (hw-446601) and patches for this:
Hw-446601: Security Advisory-Two Security Vulnerabilities in the ME906 Wireless Module
Link: Security_Advisory-Two Security Vulnerabilities in the ME906 Wireless Module-Huawei PSIRT.html
Patch download: http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htm
This article permanently updates the link address: