PT-2018-6412 · Huawei · Te50+11

Publicado

2018-03-05

·

Atualizado

2018-03-29

·

CVE-2017-17144

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Huawei DP300 versions V500R002C00 through V500R002C00SPCa00 Huawei RP200 version V500R002C00SPC200 Huawei RSE6500 versions V500R002C00SPC100 through V500R002C00SPC700 Huawei TE30 versions V100R001C10 through V100R001C10SPC800 Huawei TE30 versions V500R002C00SPC200 through V500R002C00SPCb00 Huawei TE40 versions V500R002C00SPC600 through V500R002C00SPCb00 Huawei TE50 versions V500R002C00SPC600 through V500R002C00SPCb00 Huawei TE60 versions V100R001C01SPC100 through V100R001C10SPC900 Huawei TE60 versions V500R002C00 through V500R002C00SPCd00 Huawei TE60 versions V600R006C00 through V600R006C00SPC300 Huawei TP3106 versions V100R002C00 through V100R002C00SPC800 Huawei TP3206 versions V100R002C00 through V100R002C00SPC800 Huawei TP3206 version V100R002C00SPC700 Huawei ViewPoint 9030 versions V100R011C02SPC100 through V100R011C03SPC500 Huawei eSpace U1960 version V200R003C30SPC200 Huawei eSpace U1981 versions V100R001C20SPC700 through V200R003C20SPCa00
Description: The issue is related to an overflow vulnerability in the SIP module of the affected Huawei products. When the module processes a specific amount of state, it cannot handle it, causing a denial-of-service (DoS) condition.
Recommendations: For Huawei DP300 versions V500R002C00 through V500R002C00SPCa00, update to a version that is not affected by this issue. For Huawei RP200 version V500R002C00SPC200, update to a version that is not affected by this issue. For Huawei RSE6500 versions V500R002C00SPC100 through V500R002C00SPC700, update to a version that is not affected by this issue. For Huawei TE30 versions V100R001C10 through V100R001C10SPC800, update to a version that is not affected by this issue. For Huawei TE30 versions V500R002C00SPC200 through V500R002C00SPCb00, update to a version that is not affected by this issue. For Huawei TE40 versions V500R002C00SPC600 through V500R002C00SPCb00, update to a version that is not affected by this issue. For Huawei TE50 versions V500R002C00SPC600 through V500R002C00SPCb00, update to a version that is not affected by this issue. For Huawei TE60 versions V100R001C01SPC100 through V100R001C10SPC900, update to a version that is not affected by this issue. For Huawei TE60 versions V500R002C00 through V500R002C00SPCd00, update to a version that is not affected by this issue. For Huawei TE60 versions V600R006C00 through V600R006C00SPC300, update to a version that is not affected by this issue. For Huawei TP3106 versions V100R002C00 through V100R002C00SPC800, update to a version that is not affected by this issue. For Huawei TP3206 versions V100R002C00 through V100R002C00SPC800, update to a version that is not affected by this issue. For Huawei ViewPoint 9030 versions V100R011C02SPC100 through V100R011C03SPC500, update to a version that is not affected by this issue. For Huawei eSpace U1960 version V200R003C30SPC200, update to a version that is not affected by this issue. For Huawei eSpace U1981 versions V100R001C20SPC700 through V200R003C20SPCa00, update to a version that is not affected by this issue.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17144

Produtos afetados

Dp300
Rp200
Rse6500
Te30
Te40
Te50
Te60
Tp3106
Tp3206
Viewpoint 9030
Espace U1960
Espace U1981