First published: Thu Feb 15 2018(Updated: )
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002C00, V600R006C00 have an out-of-bound read vulnerability. A remote attacker send specially crafted Session Initiation Protocol (SIP) messages to the affected products. Due to insufficient input validation, successful exploit will cause some services abnormal.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Dp300 Firmware | =v500r002c00 | |
Huawei DP300 | ||
Huawei Rp200 Firmware | =v500r002c00 | |
Huawei Rp200 Firmware | =v600r006c00 | |
Huawei Rp200 | ||
Huawei Te30 Firmware | =v100r001c10 | |
Huawei Te30 Firmware | =v500r002c00 | |
Huawei Te30 Firmware | =v600r006c00 | |
Huawei TE30 | ||
Huawei Te40 Firmware | =v500r002c00 | |
Huawei Te40 Firmware | =v600r006c00 | |
Huawei Te40 | ||
Huawei Te50 Firmware | =v500r002c00 | |
Huawei Te50 Firmware | =v600r006c00 | |
Huawei Te50 | ||
Huawei Te60 Firmware | =v100r001c01 | |
Huawei Te60 Firmware | =v100r001c10 | |
Huawei Te60 Firmware | =v500r002c00 | |
Huawei Te60 Firmware | =v600r006c00 | |
Huawei TE60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei vulnerability is CVE-2017-17283.
The severity of CVE-2017-17283 is 5.3 (medium).
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002C00, V600R006C00 are affected by CVE-2017-17283.
The vulnerability can be triggered by a remote attacker sending a specially crafted request.
Yes, Huawei has released a security advisory with a fix for CVE-2017-17283. Please refer to their website for more information.