CVE-2017-15329
CVE-2017-15329
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Feb 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.
Affected products
Huawei Technologies Co., Ltd. · UMAWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →