PT-2016-6970 · Huawei · Huawei S12700+7

Publicado

2016-09-14

·

Atualizado

2016-09-28

·

CVE-2016-6518

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei S9300 versions (affected versions not specified) Huawei S5300 versions (affected versions not specified) Huawei S5700 versions (affected versions not specified) Huawei S6700 versions (affected versions not specified) Huawei S7700 versions (affected versions not specified) Huawei S9700 versions (affected versions not specified) Huawei S12700 versions (affected versions not specified)
Description The issue is caused by a memory leak that allows remote attackers to cause a denial of service, resulting in memory consumption and potential device restart. This is achieved by sending a large number of malformed packets to the target device, exploiting the lack of adequate input validation.
Recommendations For Huawei S9300, update to a version that includes input validation to prevent memory exhaustion. For Huawei S5300, restrict access to prevent the sending of malformed packets until a patch is available. For Huawei S5700, consider implementing packet filtering to minimize the risk of exploitation. For Huawei S6700, avoid using the device for critical operations until the issue is resolved. For Huawei S7700, apply configuration changes to limit the device's exposure to malformed packets. For Huawei S9700, disable unnecessary features to reduce the attack surface. For Huawei S12700, as a temporary workaround, consider restricting device access to trusted sources only.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6518

Produtos afetados

Huawei S12700
Huawei S5300
Huawei S5700
Huawei S6700
Huawei S7700
Huawei S9300
Huawei S9700
Huawei Vrp