PT-2017-7283 · Huawei · E3272S
Kirill Nesterov
+1
·
Publicado
2017-04-02
·
Atualizado
2017-04-11
·
CVE-2015-7847
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei MBB product E3272s versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00
Description
The issue allows an attacker to send a malicious packet to the Common Gateway Interface (CGI) of a target device, causing it to fail while setting the port attribute. This results in a Denial of Service (DoS) attack.
Recommendations
For versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00, update to version E3272s-153TCPU-V200R002B491D09SP00C00 or later to resolve the issue. As a temporary workaround, consider restricting access to the CGI to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
E3272S