CVE-2017-15343: Integer Overflow
Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could system reboot.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2017-15343.
What is the severity of CVE-2017-15343?
The severity of CVE-2017-15343 is high with a severity value of 7.5.
Which Huawei AR3200 software versions are affected by CVE-2017-15343?
Huawei AR3200 software versions V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 are affected by CVE-2017-15343.
What is the vulnerability description of CVE-2017-15343?
CVE-2017-15343 is an integer overflow vulnerability in Huawei AR3200 software versions V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30. It allows a remote unauthenticated attacker to execute arbitrary code.
How can I fix CVE-2017-15343?
To fix CVE-2017-15343, apply the latest software patch or upgrade to a non-vulnerable software version provided by Huawei.