First published: Fri Mar 09 2018(Updated: )
Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Espace 7950 Firmware | =v200r003c30 | |
Huawei eSpace 7950 | ||
Huawei Espace 8950 Firmware | =v200r003c00 | |
Huawei Espace 8950 Firmware | =v200r003c30 | |
Huawei eSpace 8950 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17221 is a remote code execution vulnerability in the Import Signal Tone function of Huawei eSpace 7950 V200R003C30 and eSpace 8950 V200R003C00; V200R003C30.
CVE-2017-17221 has a severity score of 8.8, which is considered high.
CVE-2017-17221 allows an authenticated, remote attacker to execute arbitrary code in the affected products.
The affected software versions for CVE-2017-17221 are v200r003c30 for Huawei eSpace 7950 and v200r003c00/v200r003c30 for Huawei eSpace 8950.
To fix CVE-2017-17221, Huawei recommends upgrading to the fixed versions mentioned in the security advisory.