Lucene search

K
cveHuaweiCVE-2017-15315
HistoryMar 09, 2018 - 9:29 p.m.

CVE-2017-15315

2018-03-0921:29:00
CWE-772
huawei
web.nvd.nist.gov
26
cve-2017-15315
memory leak
vulnerability
huawei
nip6300
nip6600
secospace usg6300
usg6500
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

34.5%

Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200 has a memory leak vulnerability. An authenticated attacker could execute special commands many times, the memory leaking happened, which would cause the device to reset finally.

Affected configurations

Nvd
Node
huaweinip6300_firmwareMatchv500r001c20spc100
OR
huaweinip6300_firmwareMatchv500r001c20spc200
AND
huaweinip6300Match-
Node
huaweinip6600_firmwareMatchv500r001c20spc100
OR
huaweinip6600_firmwareMatchv500r001c20spc200
AND
huaweinip6600Match-
Node
huaweisecospace_usg6300_firmwareMatchv500r001c20spc100
OR
huaweisecospace_usg6300_firmwareMatchv500r001c20spc200
AND
huaweisecospace_usg6300Match-
Node
huaweisecospace_usg6500_firmwareMatchv500r001c20spc100
OR
huaweisecospace_usg6500_firmwareMatchv500r001c20spc200
AND
huaweisecospace_usg6500Match-
VendorProductVersionCPE
huaweinip6300_firmwarev500r001c20spc100cpe:2.3:o:huawei:nip6300_firmware:v500r001c20spc100:*:*:*:*:*:*:*
huaweinip6300_firmwarev500r001c20spc200cpe:2.3:o:huawei:nip6300_firmware:v500r001c20spc200:*:*:*:*:*:*:*
huaweinip6300-cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:*
huaweinip6600_firmwarev500r001c20spc100cpe:2.3:o:huawei:nip6600_firmware:v500r001c20spc100:*:*:*:*:*:*:*
huaweinip6600_firmwarev500r001c20spc200cpe:2.3:o:huawei:nip6600_firmware:v500r001c20spc200:*:*:*:*:*:*:*
huaweinip6600-cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:*
huaweisecospace_usg6300_firmwarev500r001c20spc100cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c20spc100:*:*:*:*:*:*:*
huaweisecospace_usg6300_firmwarev500r001c20spc200cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c20spc200:*:*:*:*:*:*:*
huaweisecospace_usg6300-cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:*
huaweisecospace_usg6500_firmwarev500r001c20spc100cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c20spc100:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "NIP6300,NIP6600,Secospace USG6300,Secospace USG6500",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "NIP6300 V500R001C20SPC100, V500R001C20SPC200,NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

34.5%

Related for CVE-2017-15315