PT-2016-6970 · Huawei · Huawei S12700+7

Published

2016-09-14

·

Updated

2016-09-28

·

CVE-2016-6518

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei S9300 versions (affected versions not specified) Huawei S5300 versions (affected versions not specified) Huawei S5700 versions (affected versions not specified) Huawei S6700 versions (affected versions not specified) Huawei S7700 versions (affected versions not specified) Huawei S9700 versions (affected versions not specified) Huawei S12700 versions (affected versions not specified)
Description The issue is caused by a memory leak that allows remote attackers to cause a denial of service, resulting in memory consumption and potential device restart. This is achieved by sending a large number of malformed packets to the target device, exploiting the lack of adequate input validation.
Recommendations For Huawei S9300, update to a version that includes input validation to prevent memory exhaustion. For Huawei S5300, restrict access to prevent the sending of malformed packets until a patch is available. For Huawei S5700, consider implementing packet filtering to minimize the risk of exploitation. For Huawei S6700, avoid using the device for critical operations until the issue is resolved. For Huawei S7700, apply configuration changes to limit the device's exposure to malformed packets. For Huawei S9700, disable unnecessary features to reduce the attack surface. For Huawei S12700, as a temporary workaround, consider restricting device access to trusted sources only.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6518

Affected Products

Huawei S12700
Huawei S5300
Huawei S5700
Huawei S6700
Huawei S7700
Huawei S9300
Huawei S9700
Huawei Vrp