Vulnerability Details CVE-2014-9137
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2014-9137
-
cpe:2.3:a:huawei:fusionmanager:v100r002c03
-
cpe:2.3:a:huawei:fusionmanager:v100r003c00
-
cpe:2.3:h:huawei:usg2100:-
-
cpe:2.3:h:huawei:usg2200:-
-
cpe:2.3:h:huawei:usg5100:-
-
cpe:2.3:h:huawei:usg5500:-
-
cpe:2.3:h:huawei:usg9500:-
-
cpe:2.3:o:huawei:usg2100_firmware:v300r001c00
-
cpe:2.3:o:huawei:usg2100_firmware:v300r001c00spc900
-
cpe:2.3:o:huawei:usg2200_firmware:v300r001c00
-
cpe:2.3:o:huawei:usg2200_firmware:v300r001c00spc900
-
cpe:2.3:o:huawei:usg5100_firmware:v300r001c00
-
cpe:2.3:o:huawei:usg5100_firmware:v300r001c00spc900
-
cpe:2.3:o:huawei:usg5500_firmware:v300r001c00
-
cpe:2.3:o:huawei:usg5500_firmware:v300r001c00spc900
-
cpe:2.3:o:huawei:usg9500_firmware:v200r001c01spc800
-
cpe:2.3:o:huawei:usg9500_firmware:v300r001c00