CVE-2016-8769

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
02/04/2017
Last modified:
20/04/2025

Description

Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:utps_firmware:*:*:*:*:*:*:*:* v200r003b015d15sp00c983 (including)