First published: Fri Mar 09 2018(Updated: )
Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Espace 7950 Firmware | =v200r003c30 | |
Huawei eSpace 7950 | ||
Huawei Espace 8950 Firmware | =v200r003c00 | |
Huawei Espace 8950 Firmware | =v200r003c30 | |
Huawei eSpace 8950 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-17222.
The severity of CVE-2017-17222 is high with a severity value of 8.8.
Huawei eSpace 7950 and Huawei eSpace 8950 firmware versions V200R003C30 and V200R003C00 are affected by CVE-2017-17222.
The vulnerability manifests as a remote code execution vulnerability, where an authenticated, remote attacker can craft and send packets to the affected products after uploading a Language Package.
It is recommended to refer to the official security advisory from Huawei for information on available patches or mitigations for CVE-2017-17222.