Vulnerability Name:

CVE-2012-6571 (CCN-85167)

Assigned:2012-08-04
Published:2012-08-04
Updated:2013-09-02
Summary:The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-310
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-6571

Source: CCN
Type: Huawei-SA-20120808-01-HTTP-Module
HTTP Session Management Vulnerability in HTTP Module

Source: CONFIRM
Type: UNKNOWN
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-u_194371.htm

Source: XF
Type: UNKNOWN
huawei-cve2012+571-session -hijacking(85167)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:huawei:ar_18-1x:*:*:*:*:*:*:*:* (Version <= r0130)
  • OR cpe:/h:huawei:ar_18-2x:*:*:*:*:*:*:*:* (Version <= r1712)
  • OR cpe:/h:huawei:ar_18-3x:*:*:*:*:*:*:*:* (Version <= r0118)
  • OR cpe:/h:huawei:ar_19/29/49:*:*:*:*:*:*:*:* (Version <= r2207)
  • OR cpe:/h:huawei:ar_28/46:*:*:*:*:*:*:*:* (Version <= r0311)

  • Configuration 2:
  • cpe:/h:huawei:s2000:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s2300:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s2700:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3000:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3300:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3300hi:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3500:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3700:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3900:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s5100:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s5600:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s7800:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s8500:r1631:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s8500:r1632:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:huawei:ar_19/29/49:r2207:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar_28/46:r0311:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar_18-3x:r0118:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar_18-2x:r1712:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar_18-1x:r0130:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s2300:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s2000:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s2700:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3000:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3300:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3300hi:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3700:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3500:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s3900:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s5100:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s5600:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s7800:r6305:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s8500:r1631:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:s8500:r1632:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    huawei ar 18-1x *
    huawei ar 18-2x *
    huawei ar 18-3x *
    huawei ar 19/29/49 *
    huawei ar 28/46 *
    huawei s2000 r6305
    huawei s2300 r6305
    huawei s2700 r6305
    huawei s3000 r6305
    huawei s3300 r6305
    huawei s3300hi r6305
    huawei s3500 r6305
    huawei s3700 r6305
    huawei s3900 r6305
    huawei s5100 r6305
    huawei s5600 r6305
    huawei s7800 r6305
    huawei s8500 r1631
    huawei s8500 r1632
    huawei ar 19/29/49 r2207
    huawei ar 28/46 r0311
    huawei ar 18-3x r0118
    huawei ar 18-2x r1712
    huawei ar 18-1x r0130
    huawei s2300 r6305
    huawei s2000 r6305
    huawei s2700 r6305
    huawei s3000 r6305
    huawei s3300 r6305
    huawei s3300hi r6305
    huawei s3700 r6305
    huawei s3500 r6305
    huawei s3900 r6305
    huawei s5100 r6305
    huawei s5600 r6305
    huawei s7800 r6305
    huawei s8500 r1631
    huawei s8500 r1632