CVE-2017-15317
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR150-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR160 V200R006C10, V200R006C12, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR200 V200R006C10, V200R007C00, V200R007C01, V200R008C20, V200R008C30; AR200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR2200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30; AR510 V200R006C10, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R008C20, V200R008C30; SRG1300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG2300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG3300 V200R006C10, V200R007C00, V200R008C20, V200R008C30 have an input validation vulnerability in Huawei multiple products. Due to the insufficient input validation, an unauthenticated, remote attacker may craft a malformed Stream Control Transmission Protocol (SCTP) packet and send it to the device, causing the device to read out of bounds and restart.
Affected (85)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar120 S | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 S | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 S | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar160 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 S | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 S | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar3200 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar510 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg1300 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg2300 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg3300 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.