CVE-2018-7994: High severity huawei ips module firmware vulnerability
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7994?
CVE-2018-7994 is a vulnerability found in some Huawei products, including IPS Module V500R001C50, NGFW Module V500R001C50, V500R002C10, NIP6300 V500R001C50, NIP6600 V500R001C50, NIP6800 V500R001C50, Secospace USG6600 V500R001C50, and USG9500 V500R001C50.
What is the severity of CVE-2018-7994?
CVE-2018-7994 has a severity rating of 7.5, indicating a high severity.
What is the impact of CVE-2018-7994?
CVE-2018-7994 can cause a memory leak in affected Huawei products, leading to potential stability issues and performance degradation.
How does CVE-2018-7994 work?
CVE-2018-7994 occurs when the software fails to release allocated memory properly while processing certain requests, resulting in a memory leak.
How can I fix CVE-2018-7994?
To fix CVE-2018-7994, it is recommended to update the affected Huawei products to the latest available software version provided by Huawei.