CVE-2017-17300
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Huawei S12700 V200R008C00, V200R009C00, S5700 V200R007C00, V200R008C00, V200R009C00, S6700 V200R008C00, V200R009C00, S7700 V200R008C00, V200R009C00, S9700 V200R008C00, V200R009C00 have a numeric errors vulnerability. An unauthenticated, remote attacker may send specific TCP messages with keychain authentication option to the affected products. Due to the improper validation of the messages, it will cause numeric errors when handling the messages. Successful exploit will cause the affected products to reset.
Affected (11)
Products: Huawei: S12700 Firmware, S5700 Firmware, S6700 Firmware, S7700 Firmware, S9700 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r008c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei S12700 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r007c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei S5700 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r008c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei S6700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r008c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei S7700 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r008c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei S9700 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.