← Back

CVE-2017-17157

nvd nist
Published: Feb 15, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NIP6300 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NIP6600 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, Secospace USG6300 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, Secospace USG6500 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, Secospace USG6600 V500R001C00, V500R001C00SPC100, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC301, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200PWE, V500R001C20SPC300, V500R001C20SPC300B078, V500R001C20SPC300PWE, USG9500 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC303, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE has an out-of-bounds memory access vulnerability due to insufficient input validation. An attacker could exploit it to craft special packets to trigger out-of-bounds memory access, which may further lead to system exceptions.

Affected (122)

8 products
Ips Module Firmware
Ngfw Module Firmware
Nip6300 Firmware
Nip6600 Firmware
Secospace Usg6300 Firmware
Secospace Usg6500 Firmware
Secospace Usg6600 Firmware
Usg9500 Firmware
Configuration A
14 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Ips Module
All versions
Configuration B
15 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00spc500pwe
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Ngfw Module
All versions
Configuration C
14 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Nip6300
All versions
Configuration D
13 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Running on/withPlatform Versions
Huawei
Nip6600
All versions
Configuration E
16 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00spc500pwe
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc101
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Secospace Usg6300
All versions
Configuration F
16 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc500
Version v500r001c00spc500pwe
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc101
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Secospace Usg6500
All versions
Configuration G
17 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc100
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc301
Version v500r001c00spc500
Version v500r001c00spc500pwe
Version v500r001c00sph303
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc101
Version v500r001c20spc200
Version v500r001c20spc200pwe
Version v500r001c20spc300
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Secospace Usg6600
All versions
Configuration H
17 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v500r001c00
Version v500r001c00spc200
Version v500r001c00spc300
Version v500r001c00spc303
Version v500r001c00spc500
Version v500r001c00spc500pwe
Version v500r001c00sph303
Version v500r001c00sph508
Version v500r001c20
Version v500r001c20spc100
Version v500r001c20spc100pwe
Version v500r001c20spc101
Version v500r001c20spc200
Version v500r001c20spc200b062
Version v500r001c20spc200pwe
Version v500r001c20spc300b078
Version v500r001c20spc300pwe
Running on/withPlatform Versions
Huawei
Usg9500
All versions

References (2)

Timeline

No history available yet.