First published: Fri Mar 09 2018(Updated: )
SCCP (Signalling Connection Control Part) module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 has a buffer overflow vulnerability. An attacker has to find a way to send malformed packets to the affected products repeatedly. Due to insufficient input validation, successful exploit may cause some service abnormal.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei DP300 firmware | =v500r002c00 | |
Huawei DP300 firmware | ||
Huawei RP200 | =v500r002c00 | |
Huawei RP200 | =v600r006c00 | |
Huawei RP200 firmware | ||
Huawei TE30 Firmware | =v100r001c10 | |
Huawei TE30 Firmware | =v500r002c00 | |
Huawei TE30 Firmware | =v600r006c00 | |
Huawei TE30 Firmware | ||
Huawei TE40 | =v500r002c00 | |
Huawei TE40 | =v600r006c00 | |
Huawei TE40 | ||
Huawei TE50 | =v500r002c00 | |
Huawei TE50 | =v600r006c00 | |
Huawei TE50 firmware | ||
Huawei TE60 Firmware | =v100r001c10 | |
Huawei TE60 Firmware | =v500r002c00 | |
Huawei TE60 Firmware | =v600r006c00 | |
Huawei TE60 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-17282.
CVE-2017-17282 has a severity level of 3.1 (low).
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, and TE60 V100R001C10, V500R002C00, V600R006C00 are affected by CVE-2017-17282.
CVE-2017-17282 is a buffer overflow vulnerability.
You can find more information about CVE-2017-17282 on the Huawei website: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180228-01-sccp-en.