First published: Thu Nov 19 2015(Updated: )
An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not properly initialize memory when processing timeout messages, which allows remote attackers to cause a denial of service (out-of-bounds memory access and device restart) via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei eSpace firmware | <=v100r001c20 | |
Huawei eSpace U1910 | ||
Huawei eSpace U1911 | ||
Huawei eSpace Unified Gateway U1930 | ||
Huawei eSpace U1960 | ||
Huawei eSpace Unified Gateway U1980 | ||
Huawei eSpace U1981 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8083 is classified as a denial of service vulnerability due to improper memory initialization allowing remote attackers to disrupt service.
To mitigate CVE-2015-8083, upgrade the firmware of the affected Huawei eSpace devices to version V200R003C00SPC300 or later.
CVE-2015-8083 affects Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways running firmware before V200R003C00SPC300.
The attack vector for CVE-2015-8083 is remote, allowing attackers to exploit the vulnerability without physical access to the device.
The potential impact of CVE-2015-8083 includes unauthorized denial of service, resulting in interrupted access to the affected eSpace gateways.