First published: Thu Apr 14 2016(Updated: )
Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00 before V200R006SPH002; S9300, S7700, and S9700 Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH009, and V200R006C00 before V200R006SPH003; S5720HI and S5720EI Campus series switches with software V200R006C00 before V200R006SPH002; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote authenticated users to cause a denial of service (memory consumption and device restart) by logging in and out of the (1) HTTPS or (2) SFTP server, related to SSL session information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei S5300EI | >=v200r003c00<v200r003sph011 | |
Huawei S5300EI | >=v200r005c00<v200r005sph008 | |
Huawei S5300EI | ||
Huawei S5300SI | >=v200r001c00<v200r001sph018 | |
Huawei S5300SI | >=v200r002c00<v200r003sph011 | |
Huawei S5300SI | ||
Huawei S5310HI firmware | >=v200r001c00<v200r001sph018 | |
Huawei S5310HI firmware | >=v200r002c00<v200r003sph011 | |
Huawei 5310HI | ||
Huawei 6300EI Firmware | >=v200r001c00<v200r001sph018 | |
Huawei 6300EI Firmware | >=v200r002c00<v200r003sph011 | |
Huawei S6300EI firmware | ||
Huawei S5300 firmware | >=v200r003c00<v200r003sph011 | |
Huawei S5300 firmware | >=v200r005c00<v200r005sph008 | |
Huawei S5300 firmware | >=v200r006c00<v200r006sph002 | |
Huawei S5300LI Firmware | ||
Huawei S2350EI Firmware | >=v200r003c00<v200r003sph011 | |
Huawei S2350EI Firmware | >=v200r005c00<v200r005sph008 | |
Huawei S2350EI Firmware | >=v200r006c00<v200r006sph002 | |
Huawei S2350EI Firmware | ||
Huawei Campus S9300 Firmware | >=v200r003c00<v200r003sph011 | |
Huawei Campus S9300 Firmware | >=v200r005c00<v200r005sph009 | |
Huawei Campus S9300 Firmware | >=v200r006c00<v200r006sph003 | |
Huawei Campus S9300 | ||
Huawei LSW S9700 firmware | >=v200r003c00<v200r003sph011 | |
Huawei LSW S9700 firmware | >=v200r005c00<v200r005sph009 | |
Huawei LSW S9700 firmware | >=v200r006c00<v200r006sph003 | |
Huawei Campus LSW S9700 | ||
Huawei Campus S7700 firmware | >=v200r003c00<v200r003sph011 | |
Huawei Campus S7700 firmware | >=v200r005c00<v200r005sph009 | |
Huawei Campus S7700 firmware | >=v200r006c00<v200r006sph003 | |
Huawei Campus S7700 | ||
Huawei S5720HI | >=v200r006c00<v200r006sph002 | |
Huawei S5720HI | ||
Huawei S5720EI | >=v200r006c00<v200r006sph002 | |
Huawei S5720EI Firmware | ||
Huawei S2300 Firmware | >=v100r006c05<v100r006sph022 | |
Huawei S2300 Firmware | ||
Huawei S3300 | >=v100r006c05<v100r006sph022 | |
Huawei S3300 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8677 is classified as a medium severity vulnerability due to its potential for memory leak exploitation.
To fix CVE-2015-8677, update affected Huawei switches to the specified patched firmware versions V200R003SPH011 or V200R005SPH008 and later.
CVE-2015-8677 affects models including Huawei S5300EI, S5300SI, S5310HI, S6300EI, S2350EI, and S5300LI with specific firmware versions.
The consequences of CVE-2015-8677 may include degraded performance or potential denial of service due to memory leaks in affected Huawei switches.
There are no publicly documented workarounds for CVE-2015-8677; the recommended action is to apply the appropriate firmware updates.