First published: Mon Jul 02 2018(Updated: )
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability. An unauthenticated, remote attacker has to control the peer device and craft the Signalling Connection Control Part (SCCP) messages to the target devices. Due to insufficient input validation of some values in the messages, successful exploit will cause out-of-bounds read and some services abnormal.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Dp300 Firmware | =v500r002c00 | |
Huawei DP300 | ||
Huawei Rp200 Firmware | =v500r002c00 | |
Huawei Rp200 Firmware | =v600r006c00 | |
Huawei Rp200 | ||
Huawei Te30 Firmware | =v100r001c10 | |
Huawei Te30 Firmware | =v500r002c00 | |
Huawei Te30 Firmware | =v600r006c00 | |
Huawei TE30 | ||
Huawei Te40 Firmware | =v500r002c00 | |
Huawei Te40 Firmware | =v600r006c00 | |
Huawei Te40 | ||
Huawei Te50 Firmware | =v500r002c00 | |
Huawei Te50 Firmware | =v600r006c00 | |
Huawei Te50 | ||
Huawei Te60 Firmware | =v100r001c10 | |
Huawei Te60 Firmware | =v500r002c00 | |
Huawei Te60 Firmware | =v600r006c00 | |
Huawei TE60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability-ID for this security weakness is CVE-2017-17316.
The severity level of CVE-2017-17316 is medium.
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 are affected by CVE-2017-17316.
An unauthenticated, remote attacker can exploit this vulnerability to cause an out-of-bounds read.
Please refer to the official advisory from Huawei for information on available fixes for CVE-2017-17316.