CVE-2017-15344: Integer Overflow
Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15344?
CVE-2017-15344 is an integer overflow vulnerability in Huawei AR3200 routers.
How does CVE-2017-15344 affect Huawei AR3200 routers?
CVE-2017-15344 allows a remote unauthenticated attacker to execute arbitrary code or cause a denial of service on affected Huawei AR3200 routers.
What is the severity of CVE-2017-15344?
CVE-2017-15344 has a severity score of 7.5, classified as high.
Which software versions are affected by CVE-2017-15344?
Huawei AR3200 routers with software versions V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 are affected by CVE-2017-15344.
How can I fix CVE-2017-15344?
To fix CVE-2017-15344, Huawei recommends upgrading the affected software version to one that is not vulnerable.