PT-2017-18205 · Huawei · Tp3206+2

Publicado

2017-11-22

·

Atualizado

2019-10-03

·

CVE-2017-8201

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MAX PRESENCE V100R001C00 TP3106 V100R002C00 TP3206 V100R002C00
Description The issue is related to a memory leak in the H323 protocol. An attacker can exploit this by sending crafted packets to the system after logging in as a user. Due to insufficient verification of these packets, a successful exploit could lead to a memory leak, resulting in a denial of service (DoS) condition.
Recommendations For MAX PRESENCE V100R001C00, update the H323 protocol implementation to properly verify incoming packets. For TP3106 V100R002C00, restrict access to the H323 protocol until a patch is available to fix the memory leak issue. For TP3206 V100R002C00, consider disabling the H323 protocol temporarily as a workaround until a fix is provided.

Correção

Missing Release of Resource after Effective Lifetime

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8201

Produtos afetados

Max Presence
Tp3106
Tp3206