PT-2017-14736 · Huawei · Nip6600+8

Publicado

2017-12-06

·

Atualizado

2018-02-24

·

CVE-2017-17157

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei IPS Module versions V500R001C00 through V500R001C20SPC300PWE NGFW Module versions V500R001C00 through V500R001C20SPC300PWE NIP6300 versions V500R001C00 through V500R001C20SPC300PWE NIP6600 versions V500R001C00 through V500R001C20SPC300PWE Secospace USG6300 versions V500R001C00 through V500R001C20SPC300PWE Secospace USG6500 versions V500R001C00 through V500R001C20SPC300PWE Secospace USG6600 versions V500R001C00 through V500R001C20SPC300PWE USG9500 versions V500R001C00 through V500R001C20SPC300PWE
Description The issue is related to an out-of-bounds memory access vulnerability due to insufficient input validation in IKEv2. An attacker could exploit this to craft special packets, triggering out-of-bounds memory access, which may lead to system exceptions.
Recommendations For Huawei IPS Module versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For NGFW Module versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For NIP6300 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For NIP6600 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For Secospace USG6300 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For Secospace USG6500 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For Secospace USG6600 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. For USG9500 versions V500R001C00 through V500R001C20SPC300PWE, update to a fixed version to resolve the issue. As a temporary workaround, consider disabling IKEv2 until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17157

Produtos afetados

Huawei Ips Module
Huawei Vrp
Ngfw Module
Nip6300
Nip6600
Secospace Usg6300
Secospace Usg6500
Secospace Usg6600
Usg9500