First published: Thu Nov 19 2015(Updated: )
Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS forwarding packet, aka a "VPN routing and forwarding (VRF) hopping vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei NE Router Software | <=v800r006 | |
Huawei NE Router Software | <=v800r007c00 | |
Huawei NE Router Software | ||
Huawei NE40E & NE80E | ||
Huawei NE Router Software | ||
Huawei NE40E firmware | ||
Huawei NE40E & NE80E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8087 is classified as a high severity vulnerability affecting Huawei routers.
To mitigate CVE-2015-8087, upgrade your Huawei router software to versions V800R007C10SPC100 or V800R007C00SPC100 and later.
CVE-2015-8087 allows remote attackers to conduct flooding attacks by sending crafted MPLS forwarding packets.
CVE-2015-8087 affects Huawei NE20E-S, NE40E-M, NE40E-M2 routers with software prior to specific versions.
CVE-2015-8087 is a remote vulnerability, allowing attackers to exploit it without physical access to the network.