« Volver al listado

CVE-2016-8789

Estado: ModificadaMedia (6.1)—

Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8789",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "eSpace IAD V300R001C03, V300R001C04, V300R001C06, V300R001C20 and V300R001C07",
          "versions": [
            {
              "status": "affected",
              "version": "eSpace IAD V300R001C03, V300R001C04, V300R001C06, V300R001C20 and V300R001C07"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-02T20:59:01.610",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161130-01-espace-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/94613",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161130-01-espace-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/94613",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS."
    },
    {
      "lang": "es",
      "value": "Huawei eSpace Integrated Access Device (IAD) con software V300R001C03, V300R001C04, V300R001C06, V300R001C20 y V300R001C07 permite a un atacante engañar a un usuario para que haga clic en una URL que contiene una secuencia de comandos maliciosa para obtener información del usuario o secuestrar la sesión, también conocido como XSS."
    }
  ],
  "lastModified": "2026-06-17T00:55:00.260",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AABD36A9-C669-408C-8B97-6443EB4261F2"
            },
            {
              "criteria": "cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF374D3F-67FA-4C19-90DC-7F4DA587BE3A"
            },
            {
              "criteria": "cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18A47474-2434-4E5C-AE0B-B9510526F109"
            },
            {
              "criteria": "cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c07:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1ED33178-02F2-4CE6-A7D3-60684FBDAB28"
            },
            {
              "criteria": "cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1F1582C-AAC6-4211-ACA5-59DE4E7F53BB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:espace_integrated_access_device:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "513CAF82-DDC9-4558-BC5C-407D9B51F49D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}