PT-2017-14727 · Huawei · Te50+24

Published

2017-12-06

·

Updated

2018-03-27

·

CVE-2017-17137

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei DP300 versions V500R002C00 Huawei IPS Module versions V500R001C00 through V500R001C30 Huawei NGFW Module versions V500R001C00 through V500R002C00 Huawei NIP6300 versions V500R001C00 through V500R001C30 Huawei NIP6600 versions V500R001C00 through V500R001C30 Huawei RP200 versions V500R002C00 through V600R006C00 Huawei S12700 versions V200R007C00 through V200R010C00 Huawei S1700 versions V200R006C10 through V200R010C00 Huawei S2700 versions V200R006C10 through V200R010C00 Huawei S5700 versions V200R006C00 through V200R010C00 Huawei S6700 versions V200R008C00 through V200R010C00 Huawei S7700 versions V200R007C00 through V200R010C00 Huawei S9700 versions V200R007C00 through V200R010C00 Huawei Secospace USG6300 versions V500R001C00 through V500R001C30 Huawei Secospace USG6500 versions V500R001C00 through V500R001C30 Huawei Secospace USG6600 versions V500R001C00 through V500R001C30 Huawei TE30 versions V100R001C02 through V100R001C10 and V500R002C00 through V600R006C00 Huawei TE40 versions V500R002C00 through V600R006C00 Huawei TE50 versions V500R002C00 through V600R006C00 Huawei TE60 versions V100R001C01 through V100R001C10 and V500R002C00 through V600R006C00 Huawei TP3106 version V100R002C00 Huawei TP3206 versions V100R002C00 through V100R002C10 Huawei USG9500 versions V500R001C00 through V500R001C30 Huawei ViewPoint 9030 versions V100R011C02 through V100R011C03
Description The PEM module of Huawei products has an Out-of-Bounds memory access vulnerability due to insufficient verification. An authenticated local attacker can make processing crash by a malicious certificate, which can be exploited to cause a denial of service.
Recommendations For Huawei DP300 version V500R002C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei IPS Module versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei NGFW Module versions V500R001C00 through V500R002C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei NIP6300 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei NIP6600 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei RP200 versions V500R002C00 through V600R006C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S12700 versions V200R007C00 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S1700 versions V200R006C10 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S2700 versions V200R006C10 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S5700 versions V200R006C00 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S6700 versions V200R008C00 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S7700 versions V200R007C00 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei S9700 versions V200R007C00 through V200R010C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei Secospace USG6300 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei Secospace USG6500 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei Secospace USG6600 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TE30 versions V100R001C02 through V100R001C10 and V500R002C00 through V600R006C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TE40 versions V500R002C00 through V600R006C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TE50 versions V500R002C00 through V600R006C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TE60 versions V100R001C01 through V100R001C10 and V500R002C00 through V600R006C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TP3106 version V100R002C00, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei TP3206 versions V100R002C00 through V100R002C10, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei USG9500 versions V500R001C00 through V500R001C30, update to a version that fixes the Out-of-Bounds memory access vulnerability. For Huawei ViewPoint 9030 versions V100R011C02 through V100R011C03, update to a version that fixes the Out-of-Bounds memory access vulnerability.

Fix

DoS

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17137

Affected Products

Dp300
Huawei Vrp
Ips Module
Ngfw Module
Nip6300
Nip6600
Rp200
S12700
S1700
S2700
S5700
S6700
S7700
S9700
Secospace Usg6300
Secospace Usg6500
Secospace Usg6600
Te30
Te40
Te50
Te60
Tp3106
Tp3206
Usg9500
Viewpoint 9030