Lucene search

K
cveHuaweiCVE-2017-15348
HistoryFeb 15, 2018 - 4:29 p.m.

CVE-2017-15348

2018-02-1516:29:01
CWE-20
huawei
web.nvd.nist.gov
27
huawei
v500r001c00
insufficient input validation
vulnerability
nvd
cve-2017-15348

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

60.0%

Huawei IPS Module V500R001C00, NGFW Module V500R001C00, NIP6300 V500R001C00, NIP6600 V500R001C00, Secospace USG6300 V500R001C00, Secospace USG6500 V500R001C00, Secospace USG6600 V500R001C00, USG9500 V500R001C00 have an insufficient input validation vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.

Affected configurations

Nvd
Node
huaweiips_module_firmwareMatchv500r001c00
AND
huaweiips_moduleMatch-
Node
huaweingfw_module_firmwareMatchv500r001c00
AND
huaweingfw_moduleMatch-
Node
huaweinip6300_firmwareMatchv500r001c00
AND
huaweinip6300Match-
Node
huaweinip6600_firmwareMatchv500r001c00
AND
huaweinip6600Match-
Node
huaweisecospace_usg6300_firmwareMatchv500r001c00
AND
huaweisecospace_usg6300Match-
Node
huaweisecospace_usg6600_firmwareMatchv500r001c00
AND
huaweisecospace_usg6600Match-
Node
huaweiusg9500_firmwareMatchv500r001c00
AND
huaweiusg9500Match-
Node
huaweisecospace_usg6500_firmwareMatchv500r001c00
AND
huaweisecospace_usg6500Match-
VendorProductVersionCPE
huaweiips_module_firmwarev500r001c00cpe:2.3:o:huawei:ips_module_firmware:v500r001c00:*:*:*:*:*:*:*
huaweiips_module-cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:*
huaweingfw_module_firmwarev500r001c00cpe:2.3:o:huawei:ngfw_module_firmware:v500r001c00:*:*:*:*:*:*:*
huaweingfw_module-cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:*
huaweinip6300_firmwarev500r001c00cpe:2.3:o:huawei:nip6300_firmware:v500r001c00:*:*:*:*:*:*:*
huaweinip6300-cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:*
huaweinip6600_firmwarev500r001c00cpe:2.3:o:huawei:nip6600_firmware:v500r001c00:*:*:*:*:*:*:*
huaweinip6600-cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:*
huaweisecospace_usg6300_firmwarev500r001c00cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c00:*:*:*:*:*:*:*
huaweisecospace_usg6300-cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "product": "IPS Module,NGFW Module,NIP6300,NIP6600,Secospace USG6300,Secospace USG6500,Secospace USG6600,USG9500,",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "IPS Module V500R001C00,NGFW Module V500R001C00,NIP6300 V500R001C00,NIP6600 V500R001C00,Secospace USG6300 V500R001C00,Secospace USG6500 V500R001C00,Secospace USG6600 V500R001C00,USG9500 V500R001C00,"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

60.0%

Related for CVE-2017-15348