CVE-2017-17151
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
Huawei AR100, AR100-S, AR110-S, AR120, AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR510, DP300, NetEngine16EX, RP200, SRG1300, SRG2300, SRG3300, TE30, TE40, TE50, TE60, TP3106, TP3206, ViewPoint 8660, and ViewPoint 9030 have an insufficient validation vulnerability. Since packet validation is insufficient, an unauthenticated attacker may send special H323 packets to exploit the vulnerability. Successful exploit could allow the attacker to send malicious packets and result in DOS attacks.
Affected (424)
Products: Huawei: Ar100 Firmware, Ar100 S Firmware, Ar110 S Firmware, Ar120 Firmware, Ar120 S Firmware, Ar1200 Firmware, Ar1200 S Firmware, Ar150 Firmware, Ar150 S Firmware, Ar160 Firmware, Ar200 Firmware, Ar200 S Firmware, Ar2200 Firmware, Ar2200 S Firmware, Ar3200 Firmware, Ar510 Firmware, Dp300 Firmware, Netengine16ex Firmware, Rp200 Firmware, Srg1300 Firmware, Srg2300 Firmware, Srg3300 Firmware, Te30 Firmware, Te40 Firmware, Te50 Firmware, Te60 Firmware, Tp3106 Firmware, Tp3206 Firmware, Viewpoint 8660 Firmware, Viewpoint 9030 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r008c20spc700 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r007c00spca00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar100 S | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r007c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar110 S | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar120 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar120 S | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 S | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10spc300 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 S | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar160 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 S | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 S | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar3200 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar510 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Dp300 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Netengine16ex | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00spc200 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rp200 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg1300 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg2300 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg3300 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c02spc100 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te30 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te40 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te50 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c01spc100 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te60 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c06b020 |
| Running on/with | Platform Versions |
|---|---|
Huawei Tp3106 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Tp3206 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r008c03b013sp02 |
| Running on/with | Platform Versions |
|---|---|
Huawei Viewpoint 8660 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r011c02spc100 |
| Running on/with | Platform Versions |
|---|---|
Huawei Viewpoint 9030 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.