First published: Wed Dec 06 2017(Updated: )
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR150-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR160 V200R006C10, V200R006C12, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR200 V200R006C10, V200R007C00, V200R007C01, V200R008C20, V200R008C30; AR200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR2200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30; AR510 V200R006C10, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R008C20, V200R008C30; SRG1300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG2300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG3300 V200R006C10, V200R007C00, V200R008C20, V200R008C30 have an input validation vulnerability in Huawei multiple products. Due to the insufficient input validation, an unauthenticated, remote attacker may craft a malformed Stream Control Transmission Protocol (SCTP) packet and send it to the device, causing the device to read out of bounds and restart.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei AR120-S | =v200r006c10 | |
Huawei AR120-S | =v200r007c00 | |
Huawei AR120-S | =v200r008c20 | |
Huawei AR120-S | =v200r008c30 | |
Huawei AR120 firmware | ||
Huawei ar1200 firmware | =v200r006c10 | |
Huawei ar1200 firmware | =v200r006c13 | |
Huawei ar1200 firmware | =v200r007c00 | |
Huawei ar1200 firmware | =v200r007c01 | |
Huawei ar1200 firmware | =v200r007c02 | |
Huawei ar1200 firmware | =v200r008c20 | |
Huawei ar1200 firmware | =v200r008c30 | |
Huawei AR1200 | ||
Huawei ar1200-s firmware | =v200r006c10 | |
Huawei ar1200-s firmware | =v200r007c00 | |
Huawei ar1200-s firmware | =v200r008c20 | |
Huawei ar1200-s firmware | =v200r008c30 | |
Huawei ar1200-s | ||
Huawei ar150 firmware | =v200r006c10 | |
Huawei ar150 firmware | =v200r007c00 | |
Huawei ar150 firmware | =v200r007c01 | |
Huawei ar150 firmware | =v200r007c02 | |
Huawei ar150 firmware | =v200r008c20 | |
Huawei ar150 firmware | =v200r008c30 | |
Huawei AR 150 | ||
Huawei ar150-s firmware | =v200r006c10 | |
Huawei ar150-s firmware | =v200r007c00 | |
Huawei ar150-s firmware | =v200r008c20 | |
Huawei ar150-s firmware | =v200r008c30 | |
Huawei ar150-s | ||
Huawei AR160 Firmware | =v200r006c10 | |
Huawei AR160 Firmware | =v200r006c12 | |
Huawei AR160 Firmware | =v200r007c00 | |
Huawei AR160 Firmware | =v200r007c01 | |
Huawei AR160 Firmware | =v200r007c02 | |
Huawei AR160 Firmware | =v200r008c20 | |
Huawei AR160 Firmware | =v200r008c30 | |
Huawei AR160 Firmware | ||
Huawei AR200 Firmware | =v200r006c10 | |
Huawei AR200 Firmware | =v200r007c00 | |
Huawei AR200 Firmware | =v200r007c01 | |
Huawei AR200 Firmware | =v200r008c20 | |
Huawei AR200 Firmware | =v200r008c30 | |
Huawei AR200 | ||
Huawei AR200-S Firmware | =v200r006c10 | |
Huawei AR200-S Firmware | =v200r007c00 | |
Huawei AR200-S Firmware | =v200r008c20 | |
Huawei AR200-S Firmware | =v200r008c30 | |
Huawei AR200-S Firmware | ||
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r006c13 | |
Huawei AR2200 Series Firmware | =v200r006c16 | |
Huawei AR2200 Series Firmware | =v200r007c00 | |
Huawei AR2200 Series Firmware | =v200r007c01 | |
Huawei AR2200 Series Firmware | =v200r007c02 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200 Series Firmware | =v200r008c30 | |
Huawei AR2200 Series Firmware | ||
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r007c00 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200 Series Firmware | =v200r008c30 | |
Huawei AR2200-S | ||
Huawei AR3200 | =v200r006c10 | |
Huawei AR3200 | =v200r006c11 | |
Huawei AR3200 | =v200r007c00 | |
Huawei AR3200 | =v200r007c01 | |
Huawei AR3200 | =v200r007c02 | |
Huawei AR3200 | =v200r008c00 | |
Huawei AR3200 | =v200r008c10 | |
Huawei AR3200 | =v200r008c20 | |
Huawei AR3200 | =v200r008c30 | |
Huawei AR3200 firmware | ||
Huawei AR510 Firmware | =v200r006c10 | |
Huawei AR510 Firmware | =v200r006c12 | |
Huawei AR510 Firmware | =v200r006c13 | |
Huawei AR510 Firmware | =v200r006c15 | |
Huawei AR510 Firmware | =v200r006c16 | |
Huawei AR510 Firmware | =v200r006c17 | |
Huawei AR510 Firmware | =v200r007c00 | |
Huawei AR510 Firmware | =v200r008c20 | |
Huawei AR510 Firmware | =v200r008c30 | |
Huawei AR510 | ||
Huawei SRG1300 Firmware | =v200r006c10 | |
Huawei SRG1300 Firmware | =v200r007c00 | |
Huawei SRG1300 Firmware | =v200r007c02 | |
Huawei SRG1300 Firmware | =v200r008c20 | |
Huawei SRG1300 Firmware | =v200r008c30 | |
Huawei SRG1300 | ||
Huawei SRG2300 | =v200r006c10 | |
Huawei SRG2300 | =v200r007c00 | |
Huawei SRG2300 | =v200r007c02 | |
Huawei SRG2300 | =v200r008c20 | |
Huawei SRG2300 | =v200r008c30 | |
Huawei SRG2300 | ||
Huawei SRG3300 | =v200r006c10 | |
Huawei SRG3300 | =v200r007c00 | |
Huawei SRG3300 | =v200r008c20 | |
Huawei SRG3300 | =v200r008c30 | |
Huawei SRG3300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15317 is classified as a high-severity vulnerability affecting specific Huawei router firmware versions.
To fix CVE-2017-15317, upgrade your affected Huawei router firmware to the latest version provided by Huawei.
CVE-2017-15317 affects several Huawei devices, including AR120-S, AR1200, AR150, and others running vulnerable firmware versions.
CVE-2017-15317 exploits weaknesses in the SCTP protocol implementation in the affected Huawei router firmware.
There are reports indicating that CVE-2017-15317 could be exploited in the wild, making it essential to apply patches immediately.