PT-2017-14760 · Huawei · Huawei Ar200+12

Publicado

2017-12-15

·

Atualizado

2018-03-09

·

CVE-2017-17299

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei AR120-S versions V200R006C10 through V200R007C00 Huawei AR1200 versions V200R006C10 through V200R007C02 Huawei AR1200-S versions V200R006C10 through V200R008C20 Huawei AR150 versions V200R006C10 through V200R007C02 Huawei AR150-S versions V200R006C10 through V200R007C00 Huawei AR160 versions V200R006C10 through V200R007C02 Huawei AR200 versions V200R006C10 through V200R007C00 Huawei AR200-S versions V200R006C10 through V200R007C00 Huawei AR2200 versions V200R006C10 through V200R007C02 Huawei AR2200-S versions V200R006C10 through V200R008C20 Huawei AR3200 versions V200R006C10 through V200R007C02 Huawei AR3600 versions V200R006C10 through V200R007C00 Huawei AR510 versions V200R006C12 through V200R007C00 Huawei IPS Module version V500R001C30 Huawei NIP6300 version V500R001C30 Huawei NetEngine16EX versions V200R006C10 through V200R007C00
Description The issue is related to an insufficient input validation vulnerability. An unauthenticated, remote attacker may send crafted IKE V2 messages to the affected products. Due to the insufficient validation of the messages, successful exploit will cause invalid memory access and result in a denial of service on the affected products.
Recommendations For Huawei AR120-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. For Huawei AR1200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue. For Huawei AR1200-S versions V200R006C10 through V200R008C20, update to a fixed version to resolve the issue. For Huawei AR150 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue. For Huawei AR150-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. For Huawei AR160 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue. For Huawei AR200 versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. For Huawei AR200-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. For Huawei AR2200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue. For Huawei AR2200-S versions V200R006C10 through V200R008C20, update to a fixed version to resolve the issue. For Huawei AR3200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue. For Huawei AR3600 versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. For Huawei AR510 versions V200R006C12 through V200R007C00, update to a fixed version to resolve the issue. For Huawei IPS Module version V500R001C30, update to a fixed version to resolve the issue. For Huawei NIP6300 version V500R001C30, update to a fixed version to resolve the issue. For Huawei NetEngine16EX versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue. As a temporary workaround, consider restricting access to IKE V2 messages to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17299

Produtos afetados

Huawei Ar120-S
Huawei Ar1200
Huawei Ar150
Huawei Ar160
Huawei Ar200
Huawei Ar2200
Huawei Ar3200
Huawei Ar3600
Huawei Ar510
Huawei Ips Module
Huawei Nip6300
Huawei Netengine16Ex
Huawei Vrp