Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: huawei
Published: 2017-04-02T20:00:00
Updated: 2024-08-06T02:13:21.878Z
Reserved: 2016-09-18T00:00:00
Link: CVE-2016-8273
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-04-02T20:59:00.970
Modified: 2024-11-21T02:59:03.430
Link: CVE-2016-8273
Redhat
No data.