CVE-2017-15342
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Huawei DP300 V500R002C00, TE60 V600R006C00, TP3106 V100R002C00, eSpace U1981 V200R003C30SPC100 have a denial of service vulnerability. The software does not correctly calculate the rest size in a buffer when handling SSL connections. A remote unauthenticated attacker could send a lot of crafted SSL messages to the device, successful exploit could cause no space in the buffer and then denial of service.
Affected (4)
Products: Huawei: Dp300 Firmware, Te60 Firmware, Tp3106 Firmware, Espace U1981 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Dp300 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v600r006c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te60 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Tp3106 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r003c30spc100 |
| Running on/with | Platform Versions |
|---|---|
Huawei Espace U1981 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.