PT-2014-9015 · Huawei · Usg9520+3
Published
2014-12-24
·
Updated
2017-11-08
·
CVE-2014-9697
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei USG9560/9520/9580 versions before V300R001C01SPC300
Description
The issue allows remote attackers to cause a memory leak or denial of service, resulting in memory exhaustion, reboot, and MPU switchover, via a crafted website. This can be triggered by requesting a special web page, leading to memory exhaustion and subsequent restart and switchover of the active/standby main processing unit.
Recommendations
For versions before V300R001C01SPC300, update to V300R001C01SPC300 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Vrp
Usg9520
Usg9560
Usg9580