PT-2016-7569 · Huawei · Cloudengine 6800+6

Published

2016-11-23

·

Updated

2017-04-05

·

CVE-2016-8795

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Huawei CloudEngine 12800 versions V100R002C00 through V100R006C00 Huawei CloudEngine 5800 versions V100R002C00 through V100R006C00 Huawei CloudEngine 6800 versions V100R002C00 through V100R006C00 Huawei CloudEngine 7800 versions V100R003C00 through V100R006C00 Huawei CloudEngine 8800 version V100R006C00 Huawei Secospace USG6600 version V500R001C00
Description The issue is caused by an integer overflow that can be triggered by remote, unauthenticated attackers crafting specific IPFPM packets. This is due to the lack of validation in some fields of the packet. The exploitation of this issue can cause the device to reset.
Recommendations For Huawei CloudEngine 12800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue. For Huawei CloudEngine 5800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue. For Huawei CloudEngine 6800 versions V100R002C00 through V100R006C00, update to a version that includes the fix for this issue. For Huawei CloudEngine 7800 versions V100R003C00 through V100R006C00, update to a version that includes the fix for this issue. For Huawei CloudEngine 8800 version V100R006C00, update to a version that includes the fix for this issue. For Huawei Secospace USG6600 version V500R001C00, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to IPFPM packets to minimize the risk of exploitation.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8795

Affected Products

Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Cloudengine 8800
Huawei Vrp
Secospace Usg6600