First published: Mon Mar 05 2018(Updated: )
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded. An authenticated remote attacker can place a malformed putty key file in system when a system manager load the key an infinite loop happens which lead to reboot the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Dp300 Firmware | =v500r002c00 | |
Huawei DP300 | ||
Huawei Rp200 Firmware | =v500r002c00 | |
Huawei Rp200 Firmware | =v600r006c00 | |
Huawei Rp200 | ||
Huawei Te30 Firmware | =v100r001c10 | |
Huawei Te30 Firmware | =v600r006c00 | |
Huawei TE30 | ||
Huawei Te50 Firmware | =v600r006c00 | |
Huawei Te50 | ||
Huawei Te60 Firmware | =v100r001c10 | |
Huawei Te60 Firmware | =v500r002c00 | |
Huawei Te60 Firmware | =v600r006c00 | |
Huawei TE60 | ||
Huawei Vp9660 Firmware | =v500r002c10 | |
Huawei VP9660 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17131 is medium, with a severity value of 5.7.
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V600R006C00, TE50 V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00, VP9660 V500R002C10 are affected by CVE-2017-17131.
CVE-2017-17131 is a DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded.
To fix CVE-2017-17131, apply the necessary updates or patches provided by Huawei.
You can find more information about CVE-2017-17131 on the Huawei PSIRT security advisory page.