First published: Thu Feb 15 2018(Updated: )
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NIP6300 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NIP6600 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, Secospace USG6300 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, Secospace USG6500 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, Secospace USG6600 V500R001C00, V500R001C00SPC100, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC301, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200PWE, V500R001C20SPC300, V500R001C20SPC300B078, V500R001C20SPC300PWE, USG9500 V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC303, V500R001C00SPC500, V500R001C00SPC500PWE, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC101, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE has an out-of-bounds write vulnerability due to insufficient input validation. An attacker could exploit it to craft special packets to trigger out-of-bounds memory write, which may further lead to system exceptions.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei IPS Module firmware | =v500r001c00 | |
Huawei IPS Module firmware | =v500r001c00spc200 | |
Huawei IPS Module firmware | =v500r001c00spc300 | |
Huawei IPS Module firmware | =v500r001c00spc500 | |
Huawei IPS Module firmware | =v500r001c00sph303 | |
Huawei IPS Module firmware | =v500r001c00sph508 | |
Huawei IPS Module firmware | =v500r001c20 | |
Huawei IPS Module firmware | =v500r001c20spc100 | |
Huawei IPS Module firmware | =v500r001c20spc100pwe | |
Huawei IPS Module firmware | =v500r001c20spc200 | |
Huawei IPS Module firmware | =v500r001c20spc200b062 | |
Huawei IPS Module firmware | =v500r001c20spc200pwe | |
Huawei IPS Module firmware | =v500r001c20spc300b078 | |
Huawei IPS Module firmware | =v500r001c20spc300pwe | |
Huawei IPS Module | ||
Huawei NGFW Module firmware | =v500r001c00 | |
Huawei NGFW Module firmware | =v500r001c00spc200 | |
Huawei NGFW Module firmware | =v500r001c00spc300 | |
Huawei NGFW Module firmware | =v500r001c00spc500 | |
Huawei NGFW Module firmware | =v500r001c00spc500pwe | |
Huawei NGFW Module firmware | =v500r001c00sph303 | |
Huawei NGFW Module firmware | =v500r001c00sph508 | |
Huawei NGFW Module firmware | =v500r001c20 | |
Huawei NGFW Module firmware | =v500r001c20spc100 | |
Huawei NGFW Module firmware | =v500r001c20spc100pwe | |
Huawei NGFW Module firmware | =v500r001c20spc200 | |
Huawei NGFW Module firmware | =v500r001c20spc200b062 | |
Huawei NGFW Module firmware | =v500r001c20spc200pwe | |
Huawei NGFW Module firmware | =v500r001c20spc300b078 | |
Huawei NGFW Module firmware | =v500r001c20spc300pwe | |
Huawei NGFW Module | ||
Huawei NIP6300 firmware | =v500r001c00 | |
Huawei NIP6300 firmware | =v500r001c00spc200 | |
Huawei NIP6300 firmware | =v500r001c00spc300 | |
Huawei NIP6300 firmware | =v500r001c00spc500 | |
Huawei NIP6300 firmware | =v500r001c00sph303 | |
Huawei NIP6300 firmware | =v500r001c00sph508 | |
Huawei NIP6300 firmware | =v500r001c20 | |
Huawei NIP6300 firmware | =v500r001c20spc100 | |
Huawei NIP6300 firmware | =v500r001c20spc100pwe | |
Huawei NIP6300 firmware | =v500r001c20spc200 | |
Huawei NIP6300 firmware | =v500r001c20spc200b062 | |
Huawei NIP6300 firmware | =v500r001c20spc200pwe | |
Huawei NIP6300 firmware | =v500r001c20spc300b078 | |
Huawei NIP6300 firmware | =v500r001c20spc300pwe | |
Huawei NIP6300 firmware | ||
Huawei NIP6600 | =v500r001c00 | |
Huawei NIP6600 | =v500r001c00spc200 | |
Huawei NIP6600 | =v500r001c00spc300 | |
Huawei NIP6600 | =v500r001c00spc500 | |
Huawei NIP6600 | =v500r001c00sph303 | |
Huawei NIP6600 | =v500r001c00sph508 | |
Huawei NIP6600 | =v500r001c20 | |
Huawei NIP6600 | =v500r001c20spc100 | |
Huawei NIP6600 | =v500r001c20spc100pwe | |
Huawei NIP6600 | =v500r001c20spc200 | |
Huawei NIP6600 | =v500r001c20spc200b062 | |
Huawei NIP6600 | =v500r001c20spc200pwe | |
Huawei NIP6600 | =v500r001c20spc300b078 | |
Huawei NIP6600 firmware | ||
Huawei USG6300E firmware | =v500r001c00 | |
Huawei USG6300E firmware | =v500r001c00spc200 | |
Huawei USG6300E firmware | =v500r001c00spc300 | |
Huawei USG6300E firmware | =v500r001c00spc500 | |
Huawei USG6300E firmware | =v500r001c00spc500pwe | |
Huawei USG6300E firmware | =v500r001c00sph303 | |
Huawei USG6300E firmware | =v500r001c00sph508 | |
Huawei USG6300E firmware | =v500r001c20 | |
Huawei USG6300E firmware | =v500r001c20spc100 | |
Huawei USG6300E firmware | =v500r001c20spc100pwe | |
Huawei USG6300E firmware | =v500r001c20spc101 | |
Huawei USG6300E firmware | =v500r001c20spc200 | |
Huawei USG6300E firmware | =v500r001c20spc200b062 | |
Huawei USG6300E firmware | =v500r001c20spc200pwe | |
Huawei USG6300E firmware | =v500r001c20spc300b078 | |
Huawei USG6300E firmware | =v500r001c20spc300pwe | |
Huawei Secospace USG6300 firmware | ||
Huawei Secospace USG6500 | =v500r001c00 | |
Huawei Secospace USG6500 | =v500r001c00spc200 | |
Huawei Secospace USG6500 | =v500r001c00spc300 | |
Huawei Secospace USG6500 | =v500r001c00spc500 | |
Huawei Secospace USG6500 | =v500r001c00spc500pwe | |
Huawei Secospace USG6500 | =v500r001c00sph303 | |
Huawei Secospace USG6500 | =v500r001c00sph508 | |
Huawei Secospace USG6500 | =v500r001c20 | |
Huawei Secospace USG6500 | =v500r001c20spc100 | |
Huawei Secospace USG6500 | =v500r001c20spc100pwe | |
Huawei Secospace USG6500 | =v500r001c20spc101 | |
Huawei Secospace USG6500 | =v500r001c20spc200 | |
Huawei Secospace USG6500 | =v500r001c20spc200b062 | |
Huawei Secospace USG6500 | =v500r001c20spc200pwe | |
Huawei Secospace USG6500 | =v500r001c20spc300b078 | |
Huawei Secospace USG6500 | =v500r001c20spc300pwe | |
Huawei Secospace USG6500 firmware | ||
Huawei Secospace USG6600 firmware | =v500r001c00 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc100 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc200 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc300 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc301 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc500 | |
Huawei Secospace USG6600 firmware | =v500r001c00spc500pwe | |
Huawei Secospace USG6600 firmware | =v500r001c00sph303 | |
Huawei Secospace USG6600 firmware | =v500r001c20 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc100 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc100pwe | |
Huawei Secospace USG6600 firmware | =v500r001c20spc101 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc200 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc200pwe | |
Huawei Secospace USG6600 firmware | =v500r001c20spc300 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc300b078 | |
Huawei Secospace USG6600 firmware | =v500r001c20spc300pwe | |
Huawei Secospace USG6600 firmware | ||
Huawei USG9500 firmware | =v500r001c00 | |
Huawei USG9500 firmware | =v500r001c00spc200 | |
Huawei USG9500 firmware | =v500r001c00spc300 | |
Huawei USG9500 firmware | =v500r001c00spc303 | |
Huawei USG9500 firmware | =v500r001c00spc500 | |
Huawei USG9500 firmware | =v500r001c00spc500pwe | |
Huawei USG9500 firmware | =v500r001c00sph303 | |
Huawei USG9500 firmware | =v500r001c00sph508 | |
Huawei USG9500 firmware | =v500r001c20 | |
Huawei USG9500 firmware | =v500r001c20spc100 | |
Huawei USG9500 firmware | =v500r001c20spc100pwe | |
Huawei USG9500 firmware | =v500r001c20spc101 | |
Huawei USG9500 firmware | =v500r001c20spc200 | |
Huawei USG9500 firmware | =v500r001c20spc200b062 | |
Huawei USG9500 firmware | =v500r001c20spc200pwe | |
Huawei USG9500 firmware | =v500r001c20spc300b078 | |
Huawei USG9500 firmware | =v500r001c20spc300pwe | |
Huawei USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17152 is classified as a critical security vulnerability affecting Huawei IPS Module firmware.
To fix CVE-2017-17152, update the affected Huawei IPS Module firmware to the latest version provided by Huawei.
CVE-2017-17152 affects multiple Huawei IPS Module firmware versions including v500R001C00 and v500R001C20 series.
CVE-2017-17152 could potentially allow an unauthorized user to exploit vulnerabilities in IKEv2 implementations, leading to unauthorized access or denial of service.
As of now, there are no confirmed reports of active exploitation for CVE-2017-17152, but it is recommended to apply the patch immediately.