Skip to main content

Credentials Management Errors

CVE-2013-4629

Severity High
Score 8.5/10

Summary

The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

  • MEDIUM
  • NETWORK
  • SINGLE
  • COMPLETE
  • COMPLETE
  • COMPLETE

CWE-255 - Credentials Management Errors

Weaknesses in this category are related to the management of credentials.

References

Advisory Timeline

  • Published