Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal Privilege Escalation Vulnerability."
2017-08-28T21:29:00.247
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | vcm5010_firmware | ≤ v100r001c10b010 | Yes |
| Hardware | huawei | vcm5010 | - | No |
| Operating System | huawei | vcm5020_firmware | ≤ v100r001c10b010 | Yes |
| Hardware | huawei | vcm5020 | - | No |