PT-2016-6033 · Huawei · Huawei Usg6600+9
Publicado
2016-05-11
·
Atualizado
2016-11-28
·
CVE-2016-4576
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei IPS Module versions prior to V500R001C20SPC100
Huawei NGFW Module versions prior to V500R001C20SPC100
Huawei NIP6300 versions prior to V500R001C20SPC100
Huawei NIP6600 versions prior to V500R001C20SPC100
Huawei Secospace USG6300 versions prior to V500R001C20SPC100
Huawei USG6500 versions prior to V500R001C20SPC100
Huawei USG6600 versions prior to V500R001C20SPC100
Huawei USG9500 versions prior to V500R001C20SPC100
Huawei AntiDDoS8000 versions prior to V500R001C20SPC100
Description
The issue is related to a buffer overflow in the Application Specific Packet Filtering (ASPF) functionality. This allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet with
illegitimate parameters.Recommendations
For Huawei IPS Module versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei NGFW Module versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei NIP6300 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei NIP6600 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei Secospace USG6300 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei USG6500 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei USG6600 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei USG9500 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
For Huawei AntiDDoS8000 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Antiddos8000
Huawei Ips Module
Huawei Ngfw Module
Huawei Nip6300
Huawei Nip6600
Huawei Secospace Usg6300
Huawei Usg6500
Huawei Usg6600
Huawei Usg9500
Huawei Vrp