Description
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-9121 | Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-06T02:13:21.878Z
Reserved: 2016-09-18T00:00:00.000Z
Link: CVE-2016-8273
No data.
Status : Modified
Published: 2017-04-02T20:59:00.970
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-8273
No data.
OpenCVE Enrichment
No data.
EUVD