The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.
2013-06-20T15:55:01.050
2025-04-11T00:51:21.963
Deferred
CVSSv2: 8.5 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Hardware | huawei | vp_9610 | ≤ v100r002c02b019sp05 | Yes |
| Hardware | huawei | vp_9620 | ≤ v100r002c02b019sp05 | Yes |