7.8
CVSSv3

CVE-2014-8358

Published: 11/12/2017 Updated: 29/12/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote malicious users to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei ec156_firmware v200r003b009d05sp03c1014

huawei ec176_firmware v200r003b009d05sp03c1014

huawei ec177_firmware v200r003b009d05sp03c1014

Exploits

Huawei Technologies du Mobile Broadband 160 Local Privilege Escalation Vendor: Huawei Technologies Co, Ltd Product Web Page: wwwhuaweicom Affected version: 160020316124 Summary: du Mobile Broadband is a shareware application for du EITC UAE users to support mobile broadband (3G) activation for du service provider with systems con ...