CVE Vulnerabilities

CVE-2015-8332

Improper Authentication

Published: Aug 28, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly authenticate online user identities and privileges, which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka Horizontal Privilege Escalation Vulnerability.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Vcm5010_firmwareHuawei*v100r001c10b010 (including)

Potential Mitigations

References