First published: Mon Jun 13 2016(Updated: )
Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei RSE6500 Firmware | ||
Huawei RSE6500 | =v100r001c00 | |
Huawei VP9600 Series Firmware | =v200r001c01 | |
Huawei VP9600 Series Firmware | =v200r001c02 | |
Huawei VP9600 Series Firmware | =v200r001c30 | |
Huawei VP9630 Firmware | ||
Huawei VP9650 | ||
Huawei VP 9660 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5234 has a high severity as it allows remote attackers to execute arbitrary code due to a buffer overflow in affected Huawei devices.
To fix CVE-2016-5234, update the affected Huawei VP9660, VP9650, and VP9630 devices to software version V500R002C00SPC200 or higher.
CVE-2016-5234 affects Huawei VP9660, VP9650, and VP9630 multipoint control unit devices as well as RSE6500 videoconference devices with outdated software.
CVE-2016-5234 is a buffer overflow vulnerability that can be exploited to execute arbitrary code.
Currently, there is no specific workaround for CVE-2016-5234; updating to the latest software version is recommended to mitigate the risk.