CVE-2017-17317: Buffer Overflow
Common Open Policy Service Protocol (COPS) module in Huawei USG6300 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace USG6500 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace USG6600 V100R001C00; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; TE30 V100R001C02; V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C01; V100R001C10; V500R002C00; V600R006C00 has a buffer overflow vulnerability. An unauthenticated, remote attacker has to control the peer device and send specially crafted message to the affected products. Due to insufficient input validation, successful exploit may cause some services abnormal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17317?
The severity of CVE-2017-17317 is medium with a severity value of 3.7.
Which software versions are affected by CVE-2017-17317?
Huawei USG6300 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, and Secospace USG6600 V100R001C00 are affected by CVE-2017-17317.
How can I fix CVE-2017-17317?
To fix CVE-2017-17317, please refer to the security advisory provided by Huawei at the following link: [https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180630-01-cops-en](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180630-01-cops-en)
What is the Common Open Policy Service Protocol (COPS) module?
The Common Open Policy Service Protocol (COPS) module is a protocol used for managing policy information between a policy decision point (PDP) and a policy enforcement point (PEP) in a network.
What is the CWE classification for CVE-2017-17317?
The CWE classification for CVE-2017-17317 is CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-20 (Improper Input Validation).