Security Advisory

CVE-2018-7958

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-11-27 22:00:00
Last updated 2024-08-05 06:37:59
Assigner huawei
CVSS score not scored
State PUBLISHED

Description

There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS. Due to insufficient authentication, which may be exploited to intercept and tamper with the data information.