CVE-2017-17289: Low severity Huawei Dp300 Firmware vulnerability
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability. The software does not release allocated memory properly when handling XML data. An authenticated, local attacker could upload crafted XML file repeatedly to cause memory leak and service abnormal.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this memory leak vulnerability?
The vulnerability ID for this memory leak vulnerability is CVE-2017-17289.
Which Huawei products are affected by this vulnerability?
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 are affected by this vulnerability.
What is the severity of CVE-2017-17289?
The severity of CVE-2017-17289 is low with a severity value of 3.3.
How does this memory leak vulnerability occur?
This memory leak vulnerability occurs when the software does not release allocated memory properly.
Is there a fix available for this vulnerability?
To fix this vulnerability, it is recommended to refer to the security advisory provided by Huawei at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180124-01-xml-en.