Lucene search

K
cve[email protected]CVE-2017-17330
HistoryMar 09, 2018 - 5:29 p.m.

CVE-2017-17330

2018-03-0917:29:02
CWE-772
web.nvd.nist.gov
30
huawei
ar3200
v200r005c32
v200r006c10
v200r006c11
v200r007c00
v200r007c01
v200r007c02
v200r008c00
v200r008c10
v200r008c20
v200r008c30
ngfw
module
v500r001c00
v500r001c20
v500r002c00
memory leak
vulnerability
xml
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability. The software does not release allocated memory properly when parse XML element data. An authenticated attacker could upload a crafted XML file, successful exploit could cause the system service abnormal since run out of memory.

Affected configurations

NVD
Node
huaweiar3200_firmwareMatchv200r005c32
OR
huaweiar3200_firmwareMatchv200r006c10
OR
huaweiar3200_firmwareMatchv200r006c11
OR
huaweiar3200_firmwareMatchv200r007c00
OR
huaweiar3200_firmwareMatchv200r007c01
OR
huaweiar3200_firmwareMatchv200r007c02
OR
huaweiar3200_firmwareMatchv200r008c00
OR
huaweiar3200_firmwareMatchv200r008c10
OR
huaweiar3200_firmwareMatchv200r008c20
OR
huaweiar3200_firmwareMatchv200r008c30
AND
huaweiar3200Match-
Node
huaweingfw_module_firmwareMatchv500r001c00
OR
huaweingfw_module_firmwareMatchv500r001c20
OR
huaweingfw_module_firmwareMatchv500r002c00
AND
huaweingfw_moduleMatch-

CNA Affected

[
  {
    "product": "AR3200; NGFW Module",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "AR3200 V200R005C32"
      },
      {
        "status": "affected",
        "version": "V200R006C10"
      },
      {
        "status": "affected",
        "version": "V200R006C11"
      },
      {
        "status": "affected",
        "version": "V200R007C00"
      },
      {
        "status": "affected",
        "version": "V200R007C01"
      },
      {
        "status": "affected",
        "version": "V200R007C02"
      },
      {
        "status": "affected",
        "version": "V200R008C00"
      },
      {
        "status": "affected",
        "version": "V200R008C10"
      },
      {
        "status": "affected",
        "version": "V200R008C20"
      },
      {
        "status": "affected",
        "version": "V200R008C30"
      },
      {
        "status": "affected",
        "version": "NGFW Module V500R001C00"
      },
      {
        "status": "affected",
        "version": "V500R001C20"
      },
      {
        "status": "affected",
        "version": "V500R002C00"
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Related for CVE-2017-17330