CVE-2016-8769
Estado: ModificadaMedia (6.7)—
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.58%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en
- http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/
- http://www.securityfocus.com/bid/94403
- https://www.exploit-db.com/exploits/40807/
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en
- http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/
- http://www.securityfocus.com/bid/94403
- https://www.exploit-db.com/exploits/40807/
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-8769",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "Huawei Technologies Co., Ltd.",
"product": "Huawei UTPS",
"versions": [
{
"status": "affected",
"version": "earlier than UTPS-V200R003B015D16SPC00C983"
}
]
}
]
}
],
"published": "2017-04-02T20:59:01.390",
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/",
"tags": [
"Third Party Advisory",
"URL Repurposed"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.securityfocus.com/bid/94403",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.exploit-db.com/exploits/40807/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/",
"tags": [
"Third Party Advisory",
"URL Repurposed"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/94403",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/40807/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed."
},
{
"lang": "es",
"value": "Huawei UTPS en versiones anteriores a UTPS-V200R003B015D16SPC00C983 tiene una vulnerabilidad de ruta de servicio no citada lo que pude conducir al truncamiento de rutas de consulta de servicio UTPS. Un atacante puede poner un archivo ejecutable en la ruta de búsqueda y obtener privilegios elevados después de ejecutar el archivo ejecutable."
}
],
"lastModified": "2026-06-17T00:54:58.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:utps_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F8526F6-4933-4165-A487-C0A528EB1C5C",
"versionEndIncluding": "v200r003b015d15sp00c983"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@huawei.com"
}