CVE-2016-8769
CVE-2016-8769
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.
Produtos afetados
Huawei Technologies Co., Ltd. · Huawei UTPSPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/40807/não verificadoexploitdbwww.exploit-db.com/exploits/40807não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://www.exploit-db.com/exploits/40807/http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-enhttp://www.securityfocus.com/bid/94403http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/