CVE-2012-6570: Buffer Overflow
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6570?
CVE-2012-6570 has a medium severity rating due to its potential to lead to denial of service attacks.
How do I fix CVE-2012-6570?
To remediate CVE-2012-6570, update the affected Huawei devices to the latest firmware version provided by Huawei.
What devices are affected by CVE-2012-6570?
CVE-2012-6570 affects various Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches.
What type of vulnerability is CVE-2012-6570?
CVE-2012-6570 is a vulnerability in the HTTP module that can be exploited due to improper handling of the Content-Length field.
Is there a workaround for CVE-2012-6570?
Currently, the recommended solution for CVE-2012-6570 is to apply the firmware updates rather than seeking a workaround.