CVE-2016-4577
7.5
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Usg9500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ngfw Module | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6300 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6600 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6500 | All versions |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.