PT-2018-6405 · Huawei · Huawei Vp9660

Publicado

2018-03-05

·

Atualizado

2018-03-27

·

CVE-2017-17133

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Huawei VP9660 version V500R002C10
Description: The issue is related to a null pointer reference vulnerability in the license module due to insufficient verification. An authenticated local attacker could exploit this by placing a malicious license file into the system, causing memory null pointer accessing and related processing to crash, leading to a denial of service.
Recommendations: For Huawei VP9660 version V500R002C10, ensure proper verification of license files to prevent malicious files from being placed into the system. As a temporary workaround, consider restricting access to the license module to minimize the risk of exploitation.

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17133

Produtos afetados

Huawei Vp9660