PT-2016-7569 · Huawei · Cloudengine 6800+6
Publicado
2016-11-23
·
Atualizado
2017-04-05
·
CVE-2016-8795
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei CloudEngine 12800 versions V100R002C00 through V100R006C00
Huawei CloudEngine 5800 versions V100R002C00 through V100R006C00
Huawei CloudEngine 6800 versions V100R002C00 through V100R006C00
Huawei CloudEngine 7800 versions V100R003C00 through V100R006C00
Huawei CloudEngine 8800 version V100R006C00
Huawei Secospace USG6600 version V500R001C00
Description
The issue is caused by an integer overflow that can be triggered by remote, unauthenticated attackers crafting specific IPFPM packets. This is due to the lack of validation in some fields of the packet. The exploitation of this issue can cause the device to reset.
Recommendations
For Huawei CloudEngine 12800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue.
For Huawei CloudEngine 5800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue.
For Huawei CloudEngine 6800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue.
For Huawei CloudEngine 7800 versions V100R003C00 through V100R006C00, update to a version that includes the fix for this issue.
For Huawei CloudEngine 8800 version V100R006C00, update to a version that includes the fix for this issue.
For Huawei Secospace USG6600 version V500R001C00, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to IPFPM packets to minimize the risk of exploitation.
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Cloudengine 8800
Huawei Vrp
Secospace Usg6600