CVE-2014-5394

Severity
5.9MEDIUM
EPSS
0.4%
top 37.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 14

Description

Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages12 packages

NVDhuawei/s2300_firmwarev100r006c05
NVDhuawei/s2700_firmwarev100r006c05
NVDhuawei/s3300_firmwarev100r006c05
NVDhuawei/s3700_firmwarev100r006c05
NVDhuawei/s5300_firmwarev200r001c00spc300, v200r002c00spc300, v200r003c00spc300+2

🔴Vulnerability Details

2
GHSA
GHSA-ghjw-c2v5-8vjh: Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal2022-05-14
CVEList
CVE-2014-5394: Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal2018-01-08