CVE-2017-17221: Input Validation
Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17221?
CVE-2017-17221 is a remote code execution vulnerability in the Import Signal Tone function of Huawei eSpace 7950 V200R003C30 and eSpace 8950 V200R003C00; V200R003C30.
How severe is CVE-2017-17221?
CVE-2017-17221 has a severity score of 8.8, which is considered high.
How does CVE-2017-17221 impact Huawei eSpace 7950 and eSpace 8950?
CVE-2017-17221 allows an authenticated, remote attacker to execute arbitrary code in the affected products.
What is the affected software version for CVE-2017-17221?
The affected software versions for CVE-2017-17221 are v200r003c30 for Huawei eSpace 7950 and v200r003c00/v200r003c30 for Huawei eSpace 8950.
How can CVE-2017-17221 be fixed?
To fix CVE-2017-17221, Huawei recommends upgrading to the fixed versions mentioned in the security advisory.