First published: Wed Nov 22 2017(Updated: )
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an a memory leak vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the packets, successful exploit could cause a memory leak and eventual denial of service (DoS) condition.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
=v100r001c00 | ||
Huawei Tp3106 Firmware | =v100r002c00 | |
Huawei Tp3106 | ||
Huawei Tp3206 Firmware | =v100r002c00 | |
Huawei Tp3206 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-8201.
The severity level of CVE-2017-8201 is medium (6.5).
MAX PRESENCE V100R001C00, TP3106 V100R002C00, and TP3206 V100R002C00 are affected by CVE-2017-8201.
Due to insufficient verification of packets, an attacker can exploit the vulnerability by logging in as a user and sending crafted packets to the affected products, causing a memory leak.
You can find more information about CVE-2017-8201 in the following references: [Huawei PSIRT Security Advisory](http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170927-01-h323-en) and [SecurityFocus](http://www.securityfocus.com/bid/101952).