PT-2016-7568 · Huawei · Cloudengine 6800+5

Publicado

2016-11-16

·

Atualizado

2017-04-11

·

CVE-2016-8790

CVSS v3.1

5.7

Média

VetorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei CloudEngine 5800 versions prior to V200R001C00SPC700 Huawei CloudEngine 6800 versions prior to V200R001C00SPC700 Huawei CloudEngine 7800 versions prior to V200R001C00SPC700 Huawei CloudEngine 8800 versions prior to V200R001C00SPC700 Huawei CloudEngine 12800 versions prior to V200R001C00SPC700
Description The issue is related to a buffer overflow vulnerability in the Connectivity Fault Management (CFM) function of some Huawei products. When CFM is enabled and Maintenance Association End Point (MEP) is configured on the affected device, an adjacent attacker could exploit this vulnerability by sending crafted packets to the affected system, potentially causing the main control board of the affected device to reboot.
Recommendations For Huawei CloudEngine 5800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later. For Huawei CloudEngine 6800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later. For Huawei CloudEngine 7800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later. For Huawei CloudEngine 8800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later. For Huawei CloudEngine 12800 versions prior to V200R001C00SPC700, update to V200R001C00SPC700 or later. As a temporary workaround, consider disabling the CFM function until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8790

Produtos afetados

Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Cloudengine 8800
Huawei Vrp