CVE-2017-15353: Input Validation
Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C00, TE60, V100R001C01, V100R001C10, V500R002C00, V600R006C00, TX50, V500R002C00, V600R006C00, VP9660, V500R002C00, V500R002C10, ViewPoint 8660, V100R008C03, ViewPoint 9030, V100R011C02, V100R011C03, Viewpoint 8660, V100R008C03 have an out-of-bounds read vulnerability. An attacker has to control the peer device and send specially crafted messages to the affected products. Due to insufficient input validation, successful exploit may cause some service abnormal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15353?
The severity of CVE-2017-15353 is medium with a severity value of 3.7.
Which Huawei products are affected by CVE-2017-15353?
Huawei DP300, RP200, RSE6500, TE30, TE40, TE50, TE60, TX50, VP9660, Viewpoint 8660, and Viewpoint 9030 are affected by CVE-2017-15353.
How can I fix CVE-2017-15353?
To fix CVE-2017-15353, it is recommended to apply the latest firmware updates provided by Huawei.
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-15353?
The CWE ID for CVE-2017-15353 is CWE-20 and CWE-125.
Where can I find more information about CVE-2017-15353?
More information about CVE-2017-15353 can be found on the Huawei PSIRT security advisories page.