Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20150316-01-NTPD
HistoryMar 16, 2015 - 12:00 a.m.

Security Advisory - NTPd Security Vulnerability in Multiple Huawei Products

2015-03-1600:00:00
Huawei Technologies
www.huawei.com
32

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.964

Percentile

99.6%

Huawei was notified about information released by NTP.org and CERT/CC regarding stack buffer overflow security vulnerabilities (CVE-2014-9295) in NTP daemon (ntpd) on December 19th, 2014. Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet.

Multiple Huawei products have this vulnerability. ( Vulnerability ID: HWPSIRT-2014-1276)

The NVD link is: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9295

Affected configurations

Vulners
Node
huaweiagile_controller-campus_firmwareMatchv100r001c00b001
OR
huaweidc_firmwareMatchv100r002c01spc001
OR
huaweiesightMatchv200r003c01\/c10
OR
huaweiesightMatchv200r005c00
OR
huaweiespace_firmwareMatchv100r001c01lsth06spc002
OR
huaweiespace_firmwareMatchv100r001c02\/c03
OR
huaweiespace_firmwareMatchv100r002c01
OR
huaweiespace_firmwareMatchv100r001c02
OR
huaweifusionaccessMatchv100r005c10
OR
huaweifusionaccessMatchv100r005c20
OR
huaweifusioncube_firmwareMatchv100r002c01spc100
OR
huaweifusioncube_firmwareMatchv100r002c02spc100
OR
huaweifusioncube_firmwareMatchv100r002c02spc200
OR
huaweifusioncube_firmwareMatchv100r002c02spc300
OR
huaweifusionstorageMatchv100r003c02
OR
huaweimanageoneMatchv100r002c20
OR
huaweimanageoneMatchv100r002c00\/c10
OR
huaweioceanstor_18500_firmwareMatchv100r001c00
OR
huaweioceanstor_18800_firmwareMatchv100r001c00
OR
huaweioceanstor_18800f_firmwareMatchv100r001c00
OR
huaweioceanstor_sns3096_firmwareMatchv100r003c00
OR
huaweioceanstor_hvs85t_firmwareMatchv100r001c00
OR
huaweioceanstor_hvs88t_firmwareMatchv100r001c00
OR
huaweioceanstor_s2600t_firmwareMatchv200r002c00
OR
huaweioceanstor_s5500t_firmwareMatchv200r002c00
OR
huaweioceanstor_s5600t_firmwareMatchv200r002c00
OR
huaweioceanstor_s5800t_firmwareMatchv200r002c00
OR
huaweioceanstor_s6800t_firmwareMatchv200r002c00
OR
huaweioceanstor_uds_firmwareMatchv100r002c00
OR
huaweioceanstor_uds_firmwareMatchv100r002c01
VendorProductVersionCPE
huaweiagile_controller-campus_firmwarev100r001c00b001cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r001c00b001:*:*:*:*:*:*:*
huaweidc_firmwarev100r002c01spc001cpe:2.3:a:huawei:dc_firmware:v100r002c01spc001:*:*:*:*:*:*:*
huaweiesightv200r003c01/c10cpe:2.3:a:huawei:esight:v200r003c01\/c10:*:*:*:*:*:*:*
huaweiesightv200r005c00cpe:2.3:a:huawei:esight:v200r005c00:*:*:*:*:*:*:*
huaweiespace_firmwarev100r001c01lsth06spc002cpe:2.3:o:huawei:espace_firmware:v100r001c01lsth06spc002:*:*:*:*:*:*:*
huaweiespace_firmwarev100r001c02/c03cpe:2.3:o:huawei:espace_firmware:v100r001c02\/c03:*:*:*:*:*:*:*
huaweiespace_firmwarev100r002c01cpe:2.3:o:huawei:espace_firmware:v100r002c01:*:*:*:*:*:*:*
huaweiespace_firmwarev100r001c02cpe:2.3:o:huawei:espace_firmware:v100r001c02:*:*:*:*:*:*:*
huaweifusionaccessv100r005c10cpe:2.3:a:huawei:fusionaccess:v100r005c10:*:*:*:*:*:*:*
huaweifusionaccessv100r005c20cpe:2.3:a:huawei:fusionaccess:v100r005c20:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.964

Percentile

99.6%