Vulnerabilities > CVE-2013-4629 - Credentials Management vulnerability in Huawei VP 9610 and VP 9620

047910
CVSS 8.5 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
huawei
CWE-255
nessus

Summary

The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

Vulnerable Configurations

Part Description Count
Hardware
Huawei
2

Common Weakness Enumeration (CWE)

Nessus

NASL familyHuawei Local Security Checks
NASL idHUAWEI-SA-20130513-01-VP.NASL
descriptionThe remote host is a Huawei switch running a firmware version that is affected by a fixed session ID vulnerability. A remote, unauthenticated attacker can exploit this to spoof a legitimate user.
last seen2020-06-01
modified2020-06-02
plugin id77335
published2014-08-22
reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/77335
titleHuawei VP9610 / 9620 Fixed Session ID (HWNSIRT-2013-0318)