CVE-2015-8673
Estado: ModificadaMedia (6.8)—
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-255
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-8673",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-01-12T20:59:06.560",
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/hw-462952",
"source": "cve@mitre.org"
},
{
"url": "http://www.huawei.com/en/psirt/security-advisories/hw-462952",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation."
},
{
"lang": "es",
"value": "Terminales de video conferencia multimedia Huawei TE30, TE40, TE50 y TE60 con software en versiones anteriores a V100R001C10SPC100 no requieren introducir la contraseña antigua cuando se cambia la contraseña de la cuenta Debug, lo que permite a atacantes físicamente próximos cambiar las contraseñas mediante el aprovechamiento de una estación de trabajo desatendida."
}
],
"lastModified": "2026-06-17T00:35:01.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:te30:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1146F99B-5344-4CD3-AF3F-CD3FE6F6DD91"
},
{
"criteria": "cpe:2.3:h:huawei:te40:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45C3AF58-E030-4E12-A2FD-A4337A5021ED"
},
{
"criteria": "cpe:2.3:h:huawei:te50:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4F188B3-0A63-4704-9B0D-F8DF5D973FA5"
},
{
"criteria": "cpe:2.3:h:huawei:te60:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "999117E9-90C8-4E76-90B5-7D364C0B84BF"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:te60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FEC486C-0EEE-4D46-82C9-F5AC853B2224",
"versionEndIncluding": "v100r001c10b022"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}