First published: Thu Feb 15 2018(Updated: )
Huawei S12700 V200R008C00, V200R009C00, S5700 V200R007C00, V200R008C00, V200R009C00, S6700 V200R008C00, V200R009C00, S7700 V200R008C00, V200R009C00, S9700 V200R008C00, V200R009C00 have a numeric errors vulnerability. An unauthenticated, remote attacker may send specific TCP messages with keychain authentication option to the affected products. Due to the improper validation of the messages, it will cause numeric errors when handling the messages. Successful exploit will cause the affected products to reset.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei S12700 Firmware | =v200r008c00 | |
Huawei S12700 Firmware | =v200r009c00 | |
Huawei S12700 | ||
Huawei S5700 Firmware | =v200r007c00 | |
Huawei S5700 Firmware | =v200r008c00 | |
Huawei S5700 Firmware | =v200r009c00 | |
Huawei S5700 | ||
Huawei S6700 Firmware | =v200r008c00 | |
Huawei S6700 Firmware | =v200r009c00 | |
Huawei S6700 | ||
Huawei S7700 Firmware | =v200r008c00 | |
Huawei S7700 Firmware | =v200r009c00 | |
Huawei S7700 | ||
Huawei S9700 Firmware | =v200r008c00 | |
Huawei S9700 Firmware | =v200r009c00 | |
Huawei S9700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei vulnerability is CVE-2017-17300.
The severity level of CVE-2017-17300 is high with a CVSS score of 7.5.
The software versions affected by CVE-2017-17300 include Huawei S12700 V200R008C00, V200R009C00, S5700 V200R007C00, V200R008C00, V200R009C00, S6700 V200R008C00, V200R009C00, S7700 V200R008C00, V200R009C00, and S9700 V200R008C00, V200R009C00.
CVE-2017-17300 is a numeric errors vulnerability that can be exploited by an unauthenticated, remote attacker sending specific TCP messages with keychain authentication information.
Yes, a fix for CVE-2017-17300 is available. Please refer to the Huawei security advisory for more information.