CVE-2017-8163
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR150-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR160 with software V200R006C10, V200R006C12, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR200 with software V200R006C10, V200R007C00, V200R007C01, V200R008C20, V200R008C30,AR200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR2200 with software V200R006C10, V200R006C13, V200R006C16PWE, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR2200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30,AR510 with software V200R006C10, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R008C20, V200R008C30,NetEngine16EX with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,SMC2.0 with software V100R003C10, V100R005C00, V500R002C00, V600R006C00,SRG1300 with software V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30,SRG2300 with software V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30,SRG3300 with software V200R006C10, V200R007C00, V200R008C20, V200R008C30 have an out-of-bounds read vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send specially crafted message to the target device.Successful exploit of the vulnerability could cause out-of-bounds read and system crash.
Affected (93)
Products: Huawei: Ar120 S Firmware, Ar1200 Firmware, Ar1200 S Firmware, Ar150 Firmware, Ar150 S Firmware, Ar160 Firmware, Ar200 Firmware, Ar200 S Firmware, Ar2200 Firmware, Ar2200 S Firmware, Ar3200 Firmware, Ar510 Firmware, Netengine16ex Firmware, Smc2.0 Firmware, Srg1300 Firmware, Srg2300 Firmware, Srg3300 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar120 S | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar1200 S | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar150 S | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar160 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar200 S | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar2200 S | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar3200 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ar510 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Netengine16ex | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Smc2.0 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg1300 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg2300 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r006c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Srg3300 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.