Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20151021-01-USG
HistoryOct 21, 2015 - 12:00 a.m.

Security Advisory - DHCP Snooping Vulnerability in Huawei Multiple Products

2015-10-2100:00:00
Huawei Technologies
www.huawei.com
15

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.003

Percentile

69.5%

Multiple Huawei products have “DHCP Snooping” function. When the “option82 insert” or “option82 rebuild” is enabled on interface, the device is not able to parse some specific DHCP packet correctly, making the device restart. (Vulnerability ID:HWPSIRT-2015-08052)

This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8084.

Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-457916.htm

Affected configurations

Vulners
Node
huaweiusg5500_firmwareMatchv300r001c10spc600
OR
huaweiusg2100_firmwareMatchv300r001c10spc600
OR
huaweiusg2200_firmwareMatchv300r001c10spc600
OR
huaweiusg5100_firmwareMatchv300r001c10
VendorProductVersionCPE
huaweiusg5500_firmwarev300r001c10spc600cpe:2.3:o:huawei:usg5500_firmware:v300r001c10spc600:*:*:*:*:*:*:*
huaweiusg2100_firmwarev300r001c10spc600cpe:2.3:o:huawei:usg2100_firmware:v300r001c10spc600:*:*:*:*:*:*:*
huaweiusg2200_firmwarev300r001c10spc600cpe:2.3:o:huawei:usg2200_firmware:v300r001c10spc600:*:*:*:*:*:*:*
huaweiusg5100_firmwarev300r001c10cpe:2.3:o:huawei:usg5100_firmware:v300r001c10:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.003

Percentile

69.5%

Related for HUAWEI-SA-20151021-01-USG