PT-2016-6033 · Huawei · Huawei Usg6600+9

Published

2016-05-11

·

Updated

2016-11-28

·

CVE-2016-4576

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei IPS Module versions prior to V500R001C20SPC100 Huawei NGFW Module versions prior to V500R001C20SPC100 Huawei NIP6300 versions prior to V500R001C20SPC100 Huawei NIP6600 versions prior to V500R001C20SPC100 Huawei Secospace USG6300 versions prior to V500R001C20SPC100 Huawei USG6500 versions prior to V500R001C20SPC100 Huawei USG6600 versions prior to V500R001C20SPC100 Huawei USG9500 versions prior to V500R001C20SPC100 Huawei AntiDDoS8000 versions prior to V500R001C20SPC100
Description The issue is related to a buffer overflow in the Application Specific Packet Filtering (ASPF) functionality. This allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet with illegitimate parameters.
Recommendations For Huawei IPS Module versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei NGFW Module versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei NIP6300 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei NIP6600 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei Secospace USG6300 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei USG6500 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei USG6600 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei USG9500 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later. For Huawei AntiDDoS8000 versions prior to V500R001C20SPC100, update to V500R001C20SPC100 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4576

Affected Products

Huawei Antiddos8000
Huawei Ips Module
Huawei Ngfw Module
Huawei Nip6300
Huawei Nip6600
Huawei Secospace Usg6300
Huawei Usg6500
Huawei Usg6600
Huawei Usg9500
Huawei Vrp