Overview
Huawei networking equipment use a DES encryption algorithm for password and encryption. DES is publicly known to be easily cracked.
Description
Huawei Security Advisory Huawei-SA-20120827-01-CX600 states: In multiple Huawei products, DES encryption algorithm is used for password and the encryption is not strong enough so it may be cracked (HWNSIRT-2012-0820). |
Impact
An attacker with access to the Huawei networking equipment encryption file may be able to crack the DES encryption algorithm to recover the system password. |
Solution
Apply Update
|
Huawei Security Advisory Huawei-SA-20120827-01-CX600 states the following temporary fixes: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Temporal | 5.4 | E:F/RL:OF/RC:C |
Environmental | 5.1 | CDP:LM/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Kurt Grutzmacher for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-4960 |
Date Public: | 2012-12-17 |
Date First Published: | 2013-08-05 |
Date Last Updated: | 2013-10-03 11:31 UTC |
Document Revision: | 14 |