CVE-2017-17222: Input Validation
Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-17222.
What is the severity of CVE-2017-17222?
The severity of CVE-2017-17222 is high with a severity value of 8.8.
Which products are affected by CVE-2017-17222?
Huawei eSpace 7950 and Huawei eSpace 8950 firmware versions V200R003C30 and V200R003C00 are affected by CVE-2017-17222.
How does the vulnerability in Import Language Package function in Huawei eSpace 7950 and eSpace 8950 manifest?
The vulnerability manifests as a remote code execution vulnerability, where an authenticated, remote attacker can craft and send packets to the affected products after uploading a Language Package.
Is there a fix available for CVE-2017-17222?
It is recommended to refer to the official security advisory from Huawei for information on available patches or mitigations for CVE-2017-17222.