CVE-2015-8085
moderate-risk
Published 2016-10-03
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.
Do I need to act?
-
0.04% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.9/10
Medium
NETWORK
/ LOW complexity
Affected Products (20)
Quidway S9300 Firmware
Ar Firmware
Ar Firmware
Ar Firmware
Ar Firmware
Quidway S5300 Firmware
S5300 Firmware
Quidway S9300 Firmware
Quidway S9300 Firmware
Ar Firmware
Ar Firmware
Affected Vendors
References (4)
40
/ 100
moderate-risk
Severity
20/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
20/34 · Moderate