ID

VAR-201704-0159


CVE

CVE-2016-8275


TITLE

Huawei AnyOffice Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-008216

DESCRIPTION

Huawei AnyOffice V200R006C00 could allow an authenticated, remote attacker to cause the software to deny services by uploading an XML bomb. Huawei AnyOffice Contains an input validation vulnerability.Service operation interruption (DoS) An attack may be carried out. Huawei AnyOffice is prone to a remote denial-of-service vulnerability. Successful exploits may allow the attacker to crash the affected application resulting in denial-of-service condition. Huawei AnyOffice is a mobile office application platform developed by China's Huawei (Huawei). Enterprise Mobile Management (EMM) is one of the modules that provides mobile terminal management functions. There are security vulnerabilities in Huawei AnyOffice EMM

Trust: 1.98

sources: NVD: CVE-2016-8275 // JVNDB: JVNDB-2016-008216 // BID: 93010 // VULHUB: VHN-97095

AFFECTED PRODUCTS

vendor:huaweimodel:anyofficescope:eqversion:v200r006c00

Trust: 2.4

vendor:huaweimodel:anyoffice v200r006c00scope: - version: -

Trust: 0.3

vendor:huaweimodel:anyoffice emmscope:neversion:2.6.0601.0090

Trust: 0.3

sources: BID: 93010 // JVNDB: JVNDB-2016-008216 // CNNVD: CNNVD-201701-226 // NVD: CVE-2016-8275

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-8275
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-8275
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201701-226
value: LOW

Trust: 0.6

VULHUB: VHN-97095
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2016-8275
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-97095
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-8275
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-97095 // JVNDB: JVNDB-2016-008216 // CNNVD: CNNVD-201701-226 // NVD: CVE-2016-8275

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-97095 // JVNDB: JVNDB-2016-008216 // NVD: CVE-2016-8275

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201701-226

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201701-226

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-008216

PATCH

title:huawei-sa-20160907-01-anyofficeurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160907-01-anyoffice-en

Trust: 0.8

title:Huawei AnyOffice Enterprise Mobile Management Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=66949

Trust: 0.6

sources: JVNDB: JVNDB-2016-008216 // CNNVD: CNNVD-201701-226

EXTERNAL IDS

db:NVDid:CVE-2016-8275

Trust: 2.8

db:BIDid:93010

Trust: 2.0

db:JVNDBid:JVNDB-2016-008216

Trust: 0.8

db:CNNVDid:CNNVD-201701-226

Trust: 0.7

db:VULHUBid:VHN-97095

Trust: 0.1

sources: VULHUB: VHN-97095 // BID: 93010 // JVNDB: JVNDB-2016-008216 // CNNVD: CNNVD-201701-226 // NVD: CVE-2016-8275

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160907-01-anyoffice-en

Trust: 2.0

url:http://www.securityfocus.com/bid/93010

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-8275

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2016-8275

Trust: 0.8

url:http://www.huawei.com

Trust: 0.3

sources: VULHUB: VHN-97095 // BID: 93010 // JVNDB: JVNDB-2016-008216 // CNNVD: CNNVD-201701-226 // NVD: CVE-2016-8275

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 93010

SOURCES

db:VULHUBid:VHN-97095
db:BIDid:93010
db:JVNDBid:JVNDB-2016-008216
db:CNNVDid:CNNVD-201701-226
db:NVDid:CVE-2016-8275

LAST UPDATE DATE

2025-04-20T23:31:02.350000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-97095date:2017-04-05T00:00:00
db:BIDid:93010date:2017-01-12T00:14:00
db:JVNDBid:JVNDB-2016-008216date:2017-05-02T00:00:00
db:CNNVDid:CNNVD-201701-226date:2017-01-11T00:00:00
db:NVDid:CVE-2016-8275date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-97095date:2017-04-02T00:00:00
db:BIDid:93010date:2016-09-19T00:00:00
db:JVNDBid:JVNDB-2016-008216date:2017-05-02T00:00:00
db:CNNVDid:CNNVD-201701-226date:2017-01-11T00:00:00
db:NVDid:CVE-2016-8275date:2017-04-02T20:59:01.030