CVE-2014-4707Improper Access Control in Huawei Campus S7700 Firmware

Severity
8.8HIGHNVD
EPSS
0.2%
top 60.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 17

Description

Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300 allow unauthorized users to upgrade the bootrom or bootload software, bypass a Menu protection mechanism, conduct a Menu compromise attack, or bypass a Menu/upgrade protection mechanism.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDhuawei/campus_s7700_firmwarev200r001c00spc300, v200r002c00spc100, v200r003c00spc300+2
NVDhuawei/campus_s9300_firmwarev200r001c00spc300, v200r002c00spc100, v200r003c00spc300+2
NVDhuawei/campus_s9700_firmwarev200r001c00spc300, v200r002c00spc100, v200r003c00spc300+2

🔴Vulnerability Details

2
GHSA
GHSA-jrxf-rx2w-25j6: Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V2022-05-17
CVEList
CVE-2014-4707: Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V2017-04-02
CVE-2014-4707 — Improper Access Control in Huawei | cvebase