Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20151021-01-ROUTERS
HistoryOct 21, 2015 - 12:00 a.m.

Security Advisory - VRF Hopping Vulnerability in Multiple Routers

2015-10-2100:00:00
Huawei Technologies
www.huawei.com
16

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.002 Low

EPSS

Percentile

64.4%

A VPN routing and forwarding (VRF) hopping vulnerability exists in Huawei routers. The routers do not strictly check received MPLS forwarding packets, and an attacker may exploit this vulnerability to forward crafted packets to MPLS links, which leads to flood attacks against the destination VPN. (Vulnerability ID: HWPSIRT-2015-07005)

This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8087.

Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:
<http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-457933.htm&gt;

Affected configurations

Vulners
Node
huaweine20e-x6Matchv800r006
OR
huaweine20e-x6Matchv800r007c00
OR
huaweine40e\&ne80eMatchv800r006
OR
huaweine40eMatchv800r006
OR
huaweine40eMatchv800r007c00

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.002 Low

EPSS

Percentile

64.4%

Related for HUAWEI-SA-20151021-01-ROUTERS