PT-2016-7573 · Huawei · Huawei Secospace Usg6600+3
Publicado
2016-11-25
·
Atualizado
2017-04-05
·
CVE-2016-8802
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei Secospace USG6300 versions V500R001C20SPC100 through V500R001C20SPC200
Huawei Secospace USG6500 versions V500R001C20SPC100 through V500R001C20SPC200
Huawei Secospace USG6600 versions V500R001C20SPC100 through V500R001C20SPC200
Description
The security policy processing module in certain Huawei firewall products contains a buffer overflow vulnerability. An authenticated attacker can set up a specific security policy, causing a buffer overflow that crashes the system.
Recommendations
For Huawei Secospace USG6300 versions V500R001C20SPC100 through V500R001C20SPC200, restrict access to the security policy processing module to prevent exploitation.
For Huawei Secospace USG6500 versions V500R001C20SPC100 through V500R001C20SPC200, consider disabling the security policy setup feature until a fix is available.
For Huawei Secospace USG6600 versions V500R001C20SPC100 through V500R001C20SPC200, apply configuration changes to limit the impact of a potential buffer overflow.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Secospace Usg6300
Huawei Secospace Usg6500
Huawei Secospace Usg6600
Huawei Vrp