PT-2016-7568 · Huawei · Cloudengine 6800+5
Publicado
2016-11-16
·
Atualizado
2017-04-11
·
CVE-2016-8790
CVSS v3.1
5.7
Média
| Vetor | AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei CloudEngine 5800 versions prior to V200R001C00SPC700
Huawei CloudEngine 6800 versions prior to V200R001C00SPC700
Huawei CloudEngine 7800 versions prior to V200R001C00SPC700
Huawei CloudEngine 8800 versions prior to V200R001C00SPC700
Huawei CloudEngine 12800 versions prior to V200R001C00SPC700
Description
The issue is related to a buffer overflow vulnerability in the Connectivity Fault Management (CFM) function of some Huawei products. When CFM is enabled and Maintenance Association End Point (MEP) is configured on the affected device, an adjacent attacker could exploit this vulnerability by sending crafted packets to the affected system, potentially causing the main control board of the affected device to reboot.
Recommendations
For Huawei CloudEngine 5800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later.
For Huawei CloudEngine 6800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later.
For Huawei CloudEngine 7800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later.
For Huawei CloudEngine 8800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later.
For Huawei CloudEngine 12800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later.
As a temporary workaround, consider disabling the CFM function until a patch is available.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Cloudengine 8800
Huawei Vrp