CVE-2015-8332: Huawei VCM5010 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal Privilege Escalation Vulnerability."

Affected products

  • Huawei VCM5010 Firmware: up to and including v100r001c10b010
  • Huawei VCM5020 Firmware: up to and including v100r001c10b010

Published 2017-08-28. Last modified 2026-06-17.