PT-2016-6970 · Huawei · Huawei S12700+7
Publicado
2016-09-14
·
Atualizado
2016-09-28
·
CVE-2016-6518
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei S9300 versions (affected versions not specified)
Huawei S5300 versions (affected versions not specified)
Huawei S5700 versions (affected versions not specified)
Huawei S6700 versions (affected versions not specified)
Huawei S7700 versions (affected versions not specified)
Huawei S9700 versions (affected versions not specified)
Huawei S12700 versions (affected versions not specified)
Description
The issue is caused by a memory leak that allows remote attackers to cause a denial of service, resulting in memory consumption and potential device restart. This is achieved by sending a large number of malformed packets to the target device, exploiting the lack of adequate input validation.
Recommendations
For Huawei S9300, update to a version that includes input validation to prevent memory exhaustion.
For Huawei S5300, restrict access to prevent the sending of malformed packets until a patch is available.
For Huawei S5700, consider implementing packet filtering to minimize the risk of exploitation.
For Huawei S6700, avoid using the device for critical operations until the issue is resolved.
For Huawei S7700, apply configuration changes to limit the device's exposure to malformed packets.
For Huawei S9700, disable unnecessary features to reduce the attack surface.
For Huawei S12700, as a temporary workaround, consider restricting device access to trusted sources only.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei S12700
Huawei S5300
Huawei S5700
Huawei S6700
Huawei S7700
Huawei S9300
Huawei S9700
Huawei Vrp