CVE-2016-6898

Description

XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web service outage) via a crafted XML document.

Risk Information

Base Score
6.6
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
0.083

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-6898 are affected in e9000_chassis v100r001c00NCM
Improper Access Control Vulnerability (CVE-2016-6898)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234