CVE-2017-17218
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.
Affected (13)
Products: Huawei: Dp300 Firmware, Rp200 Firmware, Te30 Firmware, Te40 Firmware, Te50 Firmware, Te60 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Dp300 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rp200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te30 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te40 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te50 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Te60 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.