CVE-2013-4629

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
20/06/2013
Last modified:
11/04/2025

Description

The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:huawei:vp_9610:*:*:*:*:*:*:*:* v100r002c02b019sp05 (including)
cpe:2.3:h:huawei:vp_9620:*:*:*:*:*:*:*:* v100r002c02b019sp05 (including)