CVE Feed

    Dashboard / CVE / CVE-2016-6838

    CVE-2016-6838

    Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.

    Published:Sep 7, 2016
    Last Modified:Apr 12, 2025
    EPS:Sep 7, 2016
    EPSS Score:0.00118
    CVSS Score:7.5

    Affected Products

    Vendor
    Huawei
    Product
    Ch121 V3 Server
    Vendor
    Huawei
    Product
    Ch121 V3 Server Firmware
    Vendor
    Huawei
    Product
    Ch140 V3 Server
    Vendor
    Huawei
    Product
    Ch140 V3 Server Firmware
    Vendor
    Huawei
    Product
    Ch220 V3 Server
    Vendor
    Huawei
    Product
    Ch220 V3 Server Firmware
    Vendor
    Huawei
    Product
    Ch222 V3 Server
    Vendor
    Huawei
    Product
    Ch222 V3 Server Firmware
    Vendor
    Huawei
    Product
    Ch226 V3 Server
    Vendor
    Huawei
    Product
    Ch226 V3 Server Firmware
    Vendor
    Huawei
    Product
    Rh1288 V3 Server
    Vendor
    Huawei
    Product
    Rh1288 V3 Server Firmware
    Vendor
    Huawei
    Product
    Rh2288 V3 Server
    Vendor
    Huawei
    Product
    Rh2288 V3 Server Firmware
    Vendor
    Huawei
    Product
    X6800 V3 Server
    Vendor
    Huawei
    Product
    X6800 V3 Server Firmware
    Vendor
    Huawei
    Product
    Xh620 V3 Server
    Vendor
    Huawei
    Product
    Xh620 V3 Server Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High