CVE-2016-3678: Input Validation
Published Apr 11, 2016
·Updated
Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.
Affected Software
10 affected components
huawei S5300 Firmware=v200r003c00spc500
huawei S5700 Firmware=v200r003c00spc500
huawei S7700 Firmware=v200r003c00spc500
huawei S9300 Firmware=v200r003c00spc500
huawei S9700 Firmware=v200r003c00spc500
huawei S5300
huawei S5700
huawei S7700
huawei S9300
huawei S9700
Event History
Apr 11, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3678?
CVE-2016-3678 has a medium severity rating as it can lead to a denial of service through switch restarts.
2
How do I fix CVE-2016-3678?
To fix CVE-2016-3678, upgrade the affected Huawei switch firmware to version V200R003SPH012 or later.
3
Which devices are affected by CVE-2016-3678?
CVE-2016-3678 affects Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches running specific firmware versions.
4
What type of attack does CVE-2016-3678 facilitate?
CVE-2016-3678 facilitates a denial of service attack that can cause switches to restart.
5
Can CVE-2016-3678 be exploited remotely?
Yes, CVE-2016-3678 can be exploited remotely by attackers sending crafted traffic to the affected devices.