The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-261327.htm | vendor advisory |